Oval Definition:oval:com.redhat.rhsa:def:20070501
Revision Date:2008-03-20Version:637
Title:RHSA-2007:0501: libexif integer overflow (Moderate)
Description:The libexif package contains the EXIF library. Applications use this library to parse EXIF image files.

  • An integer overflow flaw was found in the way libexif parses EXIF image tags. If a victim opens a carefully crafted EXIF image file it could cause the application linked against libexif to execute arbitrary code or crash. (CVE-2007-4168)

    Users of libexif should upgrade to these updated packages, which contain a backported patch and are not vulnerable to this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-4168
    RHSA-2007:0501
    RHSA-2007:0501-02
    RHSA-2007:0501-02
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • libexif is earlier than 0:0.5.12-5.1.0.2
  • AND libexif is signed with Red Hat redhatrelease2 key
  • libexif-devel is earlier than 0:0.5.12-5.1.0.2
  • AND libexif-devel is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • libexif is earlier than 0:0.6.13-4.0.2.el5
  • AND libexif is signed with Red Hat redhatrelease2 key
  • libexif-devel is earlier than 0:0.6.13-4.0.2.el5
  • AND libexif-devel is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • libexif is earlier than 0:0.5.12-5.1.0.2
  • AND libexif is signed with Red Hat master key
  • libexif-devel is earlier than 0:0.5.12-5.1.0.2
  • AND libexif-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • libexif is earlier than 0:0.6.13-4.0.2.el5
  • AND libexif is signed with Red Hat redhatrelease key
  • libexif-devel is earlier than 0:0.6.13-4.0.2.el5
  • AND libexif-devel is signed with Red Hat redhatrelease key
  • BACK