In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libexif | Libexif_project | * | 0.6.25 (including) |
| Red Hat Enterprise Linux 10 | RedHat | libexif-0:0.6.24-9.el10_2.1 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | libexif-0:0.6.24-9.el10_0.1 | * |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | RedHat | libexif-0:0.6.22-3.el7_9 | * |
| Red Hat Enterprise Linux 8 | RedHat | libexif-0:0.6.22-6.el8_10 | * |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | libexif-0:0.6.22-5.el8_4.1 | * |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | libexif-0:0.6.22-5.el8_4.1 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | libexif-0:0.6.22-5.el8_6.1 | * |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | RedHat | libexif-0:0.6.22-5.el8_6.1 | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | libexif-0:0.6.22-5.el8_8.1 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | libexif-0:0.6.22-5.el8_8.1 | * |
| Red Hat Enterprise Linux 9 | RedHat | libexif-0:0.6.22-6.el9_8.1 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | libexif-0:0.6.22-6.el9_2.1 | * |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | RedHat | libexif-0:0.6.22-6.el9_4.1 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | libexif-0:0.6.22-6.el9_6.1 | * |
| Libexif | Ubuntu | devel | * |
| Libexif | Ubuntu | esm-infra-legacy/trusty | * |
| Libexif | Ubuntu | esm-infra-legacy/xenial | * |
| Libexif | Ubuntu | esm-infra/bionic | * |
| Libexif | Ubuntu | esm-infra/focal | * |
| Libexif | Ubuntu | esm-infra/xenial | * |
| Libexif | Ubuntu | jammy | * |
| Libexif | Ubuntu | noble | * |
| Libexif | Ubuntu | questing | * |
| Libexif | Ubuntu | resolute | * |