9.3

CVE-2007-2645

Exploit
Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted EXIF data, involving the (1) doff or (2) s variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LibexifLibexif Version0.5
LibexifLibexif Version0.5.12
LibexifLibexif Version0.6.9
LibexifLibexif Version0.6.11
LibexifLibexif Version0.6.12
LibexifLibexif Version0.6.13
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.16% 0.959
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/26083
http://www.novell.com/linux/security/advisories/2007_14_sr.html
http://osvdb.org/35978
http://secunia.com/advisories/25235
Patch
Vendor Advisory
http://secunia.com/advisories/25540
http://secunia.com/advisories/25569
http://secunia.com/advisories/25599
http://secunia.com/advisories/25621
http://secunia.com/advisories/25932
http://secunia.com/advisories/28776
http://security.gentoo.org/glsa/glsa-200706-01.xml
http://sourceforge.net/project/shownotes.php?release_id=507447
Patch
http://sourceforge.net/tracker/index.php?func=detail&aid=1716196&group_id=12272&atid=112272
http://www.debian.org/security/2008/dsa-1487
http://www.mandriva.com/security/advisories?name=MDKSA-2007:118
http://www.novell.com/linux/security/advisories/2007_39_libexif.html
http://www.securityfocus.com/archive/1/470502/100/100/threaded
http://www.securityfocus.com/bid/23927
Patch
Exploit
http://www.ubuntu.com/usn/usn-471-1
http://www.vupen.com/english/advisories/2007/1761
https://exchange.xforce.ibmcloud.com/vulnerabilities/34233
https://issues.rpath.com/browse/RPL-1431