Vulnerability Name:

CVE-2007-2645 (CCN-34233)

Assigned:2007-05-10
Published:2007-05-10
Updated:2018-10-16
Summary:Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted EXIF data, involving the (1) doff or (2) s variable.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2007-2645

Source: OSVDB
Type: UNKNOWN
35978

Source: CCN
Type: SA25235
libexif EXIF Information Handling Vulnerability

Source: SECUNIA
Type: Patch, Vendor Advisory
25235

Source: SECUNIA
Type: UNKNOWN
25540

Source: SECUNIA
Type: UNKNOWN
25569

Source: SECUNIA
Type: UNKNOWN
25599

Source: SECUNIA
Type: UNKNOWN
25621

Source: SECUNIA
Type: UNKNOWN
25932

Source: SECUNIA
Type: UNKNOWN
26083

Source: SECUNIA
Type: UNKNOWN
28776

Source: GENTOO
Type: UNKNOWN
GLSA-200706-01

Source: CONFIRM
Type: Patch
http://sourceforge.net/project/shownotes.php?release_id=507447

Source: CCN
Type: SourceForge.net: Files
EXIF Tag Parsing Library - File Release Notes and Changelog - Release Name: 0.6.14

Source: CCN
Type: Libexif Web site
Project: EXIF Tag Parsing Library: Summary

Source: MISC
Type: UNKNOWN
http://sourceforge.net/tracker/index.php?func=detail&aid=1716196&group_id=12272&atid=112272

Source: DEBIAN
Type: UNKNOWN
DSA-1487

Source: DEBIAN
Type: DSA-1487
libexif -- several vulnerabilities

Source: CCN
Type: GLSA-200706-01
libexif: Integer overflow vulnerability

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:118

Source: SUSE
Type: UNKNOWN
SUSE-SR:2007:014

Source: SUSE
Type: UNKNOWN
SUSE-SA:2007:039

Source: CCN
Type: OSVDB ID: 35978
libexif exif-data.c exif_data_load_data_entry Function EXIF Data Handling Overflow

Source: BUGTRAQ
Type: UNKNOWN
20070604 FLEA-2007-0024-1: libexif

Source: BID
Type: Exploit, Patch
23927

Source: CCN
Type: BID-23927
LibEXIF Exif_Data_Load_Data_Entry Remote Integer Overflow Vulnerability

Source: CCN
Type: TLSA-2007-44
libexif Integer overflow

Source: CCN
Type: USN-471-1
libexif vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-471-1

Source: VUPEN
Type: UNKNOWN
ADV-2007-1761

Source: XF
Type: UNKNOWN
libexif-exifdataloaddata-integer-overflow(34233)

Source: XF
Type: UNKNOWN
libexif-exifdataloaddata-integer-overflow(34233)

Source: CONFIRM
Type: UNKNOWN
https://issues.rpath.com/browse/RPL-1431

Source: SUSE
Type: SUSE-SA:2007:039
libexif security problems

Source: SUSE
Type: SUSE-SR:2007:014
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:libexif:libexif:0.5:*:*:*:*:*:*:*
  • OR cpe:/a:libexif:libexif:0.5.12:*:*:*:*:*:*:*
  • OR cpe:/a:libexif:libexif:0.6.9:*:*:*:*:*:*:*
  • OR cpe:/a:libexif:libexif:0.6.11:*:*:*:*:*:*:*
  • OR cpe:/a:libexif:libexif:0.6.12:*:*:*:*:*:*:*
  • OR cpe:/a:libexif:libexif:0.6.13:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:libexif:libexif:0.6.13:*:*:*:*:*:*:*
  • AND
  • cpe:/o:suse:suse_linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:novell:linux_desktop:9:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*
  • OR cpe:/a:novell:open_enterprise_server:*:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:6.06::lts:*:*:*:*:*
  • OR cpe:/o:novell:suse_linux_enterprise_server:10:sp2:itanium_ia64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:fuji:*:*:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:*:*:personal:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:*:*:home:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:*:*:multimedia:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:7.04:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1::x86-64:*:*:*:*:*
  • OR cpe:/a:novell:open_enterprise_server:*:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:10.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20072645
    V
    CVE-2007-2645
    2015-11-16
    oval:org.mitre.oval:def:8088
    P
    DSA-1487 libexif -- several vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:18662
    P
    DSA-1487-1 libexif - several vulnerabilities
    2014-06-23
    oval:org.debian:def:1487
    V
    several vulnerabilities
    2008-02-08
    BACK
    libexif libexif 0.5
    libexif libexif 0.5.12
    libexif libexif 0.6.9
    libexif libexif 0.6.11
    libexif libexif 0.6.12
    libexif libexif 0.6.13
    libexif libexif 0.6.13
    suse suse linux *
    gentoo linux *
    mandrakesoft mandrake linux corporate server 3.0
    novell linux desktop 9
    debian debian linux 3.1
    novell open enterprise server *
    canonical ubuntu 6.06
    novell suse linux enterprise server 10 sp2
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 3.0
    turbolinux turbolinux fuji
    turbolinux turbolinux personal *
    turbolinux turbolinux home *
    turbolinux turbolinux multimedia *
    mandrakesoft mandrake linux 2007.1
    mandrakesoft mandrake linux 2008.0
    debian debian linux 4.0
    canonical ubuntu 7.04
    mandrakesoft mandrake linux 2007.1
    novell open enterprise server *
    novell opensuse 10.2