Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Debian: DSA-1533-1 Critical: Exiftags Input Flaws Cause Code Execution

debian
Calendar Grey March 27, 2008
Debian Logo
The Debian Security Notice DSA-1533-1 provides solutions for exiftags, tackling numerous significant vulnerabilities.
Inadequate EXIF property validation could lead to invalid memory accesses if executed on a maliciously crafted image, potentially including heap corruption and the exec...

Summary


Inadequate EXIF property validation could lead to invalid memory
accesses if executed on a maliciously crafted image, potentially
including heap corruption and the execution of arbitrary code.

CVE-2007-6355

Flawed data validation could lead to integer overflows, causing
other invalid memory accesses, also with the potential for memory
corruption or arbitrary code execution.

CVE-2007-6356

Cyclical EXIF image file directory (IFD) references could cause
a denial of service (infinite loop).

For the stable distribution (etch), these problems have been fixed in
version 0.98-1.1+etch1.

The old stable distribution (sarge) cannot be fixed synchronously
with the Etch version due to a technical limitation in the Debian
archive management scripts.

For the unstable distribution (sid), these problems have been fixed in
version 1.01-0.1.

We recommend that you upgrade your exiftags package.


Debian 4.0 (stable)
- -------------------Stable updates are av...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here