CVE Vulnerabilities

CVE-2006-4168

Published: Jun 14, 2007 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Libexif Libexif 0.6.9 0.6.9
Libexif Libexif 0.6.11 0.6.11
Libexif Libexif 0.6.12 0.6.12
Libexif Libexif 0.6.13 0.6.13
Libexif Libexif 0.6.14 0.6.14
Libexif Libexif 0.6.15 0.6.15
Red Hat Enterprise Linux 4 RedHat libexif-0:0.5.12-5.1.0.2 *
Red Hat Enterprise Linux 5 RedHat libexif-0:0.6.13-4.0.2.el5 *
Libexif Ubuntu dapper *
Libexif Ubuntu devel *
Libexif Ubuntu edgy *
Libexif Ubuntu feisty *

References