CVE Vulnerabilities

CVE-2005-4676

Published: Dec 31, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.

Affected Software

NameVendorStart VersionEnd Version
Exiv2Andreas_huggel0.3 (including)0.3 (including)
Exiv2Andreas_huggel0.4 (including)0.4 (including)
Exiv2Andreas_huggel0.5 (including)0.5 (including)
Exiv2Andreas_huggel0.6 (including)0.6 (including)
Exiv2Andreas_huggel0.6.1 (including)0.6.1 (including)
Exiv2Andreas_huggel0.6.2 (including)0.6.2 (including)
Exiv2Andreas_huggel0.7 (including)0.7 (including)
Exiv2Andreas_huggel0.8 (including)0.8 (including)

References