6.8

CVE-2006-4168

Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LibexifLibexif Version0.6.9
LibexifLibexif Version0.6.11
LibexifLibexif Version0.6.12
LibexifLibexif Version0.6.13
LibexifLibexif Version0.6.14
LibexifLibexif Version0.6.15
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.3% 0.899
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/26083
http://www.novell.com/linux/security/advisories/2007_14_sr.html
http://secunia.com/advisories/25932
http://www.novell.com/linux/security/advisories/2007_39_libexif.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=543
Patch
Vendor Advisory
http://osvdb.org/35379
http://secunia.com/advisories/25642
Patch
Vendor Advisory
http://secunia.com/advisories/25645
http://secunia.com/advisories/25674
http://secunia.com/advisories/25717/
http://secunia.com/advisories/25746
http://secunia.com/advisories/25768
http://secunia.com/advisories/25820
http://secunia.com/advisories/25842
http://security.gentoo.org/glsa/glsa-200706-09.xml
http://sourceforge.net/project/shownotes.php?release_id=515385
Patch
http://www.debian.org/security/2007/dsa-1310
http://www.mandriva.com/security/advisories?name=MDKSA-2007:128
http://www.securityfocus.com/archive/1/472046/100/0/threaded
http://www.securityfocus.com/bid/24461
http://www.securitytracker.com/id?1018240
http://www.ubuntu.com/usn/usn-478-1
http://www.vupen.com/english/advisories/2007/2165
https://exchange.xforce.ibmcloud.com/vulnerabilities/34851
https://issues.rpath.com/browse/RPL-1482
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9349
https://rhn.redhat.com/errata/RHSA-2007-0501.html