Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libexif | Libexif | 0.6.9 (including) | 0.6.9 (including) |
| Red Hat Enterprise Linux 4 | RedHat | libexif-0:0.5.12-5.1 | * |
| Libexif | Ubuntu | dapper | * |
| Libexif | Ubuntu | devel | * |
| Libexif | Ubuntu | edgy | * |
| Libexif | Ubuntu | feisty | * |