Revision Date: | 2013-04-29 | Version: | 11 |
Title: | Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag. |
Description: | Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag. |
Family: | unix | Class: | vulnerability |
Status: | ACCEPTED | Reference(s): | CVE-2005-0664
|
Platform(s): | CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 4
| Product(s): | |
Definition Synopsis |
RHEL4, CentOS4 or Oracle Linux 4 The operating system installed on the system is Red Hat Enterprise Linux 4
OR CentOS Linux 4.x
OR Oracle Linux 4.x
AND Configuration section
libexif-devel is earlier than 0:0.5.12-5.1
OR libexif is earlier than 0:0.5.12-5.1
|