Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian: DSA-2559-1 Critical Libexif Buffer Overflow Remote Exploit

debian
Calendar Grey October 17, 2012
Debian Logo
Ubuntu's USN-4805-1 highlights significant vulnerabilities in libexif that necessitate prompt remediation. Discover further details here.
Several vulnerabilities were found in libexif, a library used to parse EXIF meta-data on camera files

Summary

Several vulnerabilities were found in libexif, a library used to parse EXIF
meta-data on camera files.

CVE-2012-2812: A heap-based out-of-bounds array read in the
exif_entry_get_value function allows remote attackers to cause a denial of
service or possibly obtain potentially sensitive information from process
memory via an image with crafted EXIF tags.

CVE-2012-2813: A heap-based out-of-bounds array read in the
exif_convert_utf16_to_utf8 function allows remote attackers to cause a denial
of service or possibly obtain potentially sensitive information from process
memory via an image with crafted EXIF tags.

CVE-2012-2814: A buffer overflow in the exif_entry_format_value function
allows remote attackers to cause a denial of service or possibly execute
arbitrary code via an image with crafted EXIF tags.

CVE-2012-2836: A heap-based out-of-bounds array read in the
exif_data_load_data function allows remote attackers to cause a denial of
service or possibly obtain potentially sensitive information fro...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: libexif
CVE ID: CVE-2012-2812 CVE-2012-2813 CVE-2012-2814 CVE-2012-2836

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here