Oval Definition:oval:org.mitre.oval:def:7793
Revision Date:2014-06-23Version:17
Title:DSA-1533 exiftags -- insufficient input sanitising
Description:Christian Schmid and Meder Kydyraliev (Google Security) discovered a number of vulnerabilities in exiftags, a utility for extracting EXIF metadata from JPEG images. The Common Vulnerabilities and Exposures project identified the following three problems: Inadequate EXIF property validation could lead to invalid memory accesses if executed on a maliciously crafted image, potentially including heap corruption and the execution of arbitrary code. Flawed data validation could lead to integer overflows, causing other invalid memory accesses, also with the potential for memory corruption or arbitrary code execution. Cyclical EXIF image file directory (IFD) references could cause a denial of service (infinite loop).
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-6354
CVE-2007-6355
CVE-2007-6356
DSA-1533
Platform(s):Debian GNU/Linux 3.1
Debian GNU/Linux 4.0
Product(s):exiftags
Definition Synopsis
  • Release section
  • Debian GNU/Linux 4.0 is installed.
  • AND Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is powerpc
  • OR Installed architecture is i386
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is mipsel
  • OR Installed architecture is arm
  • AND exiftags is earlier than 0.98-1.1+etch1
  • OR Release section
  • Debian GNU/Linux 3.1 is installed
  • AND Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is m68k
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND exiftags is earlier than 0.98-1.1+0sarge1
  • BACK