Vulnerability Name: | CVE-2006-4168 (CCN-34851) | ||||||||||||||||||||||||
Assigned: | 2006-08-16 | ||||||||||||||||||||||||
Published: | 2007-06-13 | ||||||||||||||||||||||||
Updated: | 2018-10-17 | ||||||||||||||||||||||||
Summary: | Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-Other CWE-190 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2006-4168 Source: IDEFENSE Type: Patch, Vendor Advisory 20070613 Multiple Vendor libexif Integer Overflow Heap Corruption Vulnerability Source: OSVDB Type: UNKNOWN 35379 Source: CCN Type: RHSA-2007-0501 Moderate: libexif integer overflow Source: CCN Type: SA25642 libexif EXIF Information Integer Overflow Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 25642 Source: SECUNIA Type: UNKNOWN 25645 Source: SECUNIA Type: UNKNOWN 25674 Source: SECUNIA Type: UNKNOWN 25717 Source: SECUNIA Type: UNKNOWN 25746 Source: SECUNIA Type: UNKNOWN 25768 Source: SECUNIA Type: UNKNOWN 25820 Source: SECUNIA Type: UNKNOWN 25842 Source: SECUNIA Type: UNKNOWN 25932 Source: SECUNIA Type: UNKNOWN 26083 Source: CCN Type: SA51857 Avaya CMS Oracle Solaris Multiple Vulnerabilities Source: GENTOO Type: UNKNOWN GLSA-200706-09 Source: CCN Type: SECTRACK ID: 1018240 libexif Integer Overflow in exif_data_load_data_entry() May Let Remote Users Crash the Application or Execute Arbitrary Code Source: CONFIRM Type: Patch http://sourceforge.net/project/shownotes.php?release_id=515385 Source: CCN Type: SourceForge.net EXIF Tag Parsing Library: Summary Source: CCN Type: ASA-2007-286 libexif integer overflow (RHSA-2007-0501) Source: DEBIAN Type: UNKNOWN DSA-1310 Source: DEBIAN Type: DSA-1310 libexif -- integer overflow Source: CCN Type: GLSA-200706-09 libexif: Buffer overflow Source: MANDRIVA Type: UNKNOWN MDKSA-2007:128 Source: SUSE Type: UNKNOWN SUSE-SR:2007:014 Source: SUSE Type: UNKNOWN SUSE-SA:2007:039 Source: CCN Type: OSVDB ID: 35379 libexif EXIF Tagged Image exif_data_load_data_entry Function Overflow Source: BUGTRAQ Type: UNKNOWN 20070622 FLEA-2007-0028-1: libexif Source: BID Type: UNKNOWN 24461 Source: CCN Type: BID-24461 EXIF Library EXIF File Processing Integer Overflow Vulnerability Source: SECTRACK Type: UNKNOWN 1018240 Source: CCN Type: USN-478-1 libexif vulnerability Source: UBUNTU Type: UNKNOWN USN-478-1 Source: VUPEN Type: UNKNOWN ADV-2007-2165 Source: CCN Type: ASA-2012-056 Multiple Vulnerabilities in Libexif (Oracle January 2012) Source: CCN Type: ASA-2012-176 Oracle Solaris Critical Update (CVE-2012-0539) Source: XF Type: UNKNOWN multiple-libexif-exifdataloaddataentry-bo(34851) Source: XF Type: UNKNOWN multiple-libexif-exifdataloaddataentry-bo(34851) Source: CONFIRM Type: UNKNOWN https://issues.rpath.com/browse/RPL-1482 Source: CCN Type: iDefense Labs PUBLIC ADVISORY: 06.13.07 Multiple Vendor libexif Integer Overflow Heap Corruption Vulnerability Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9349 Source: REDHAT Type: UNKNOWN RHSA-2007:0501 Source: SUSE Type: SUSE-SA:2007:039 libexif security problems Source: SUSE Type: SUSE-SR:2007:014 SUSE Security Summary Report | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Configuration RedHat 9: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |