Vulnerability Name:

CVE-2007-6353 (CCN-39118)

Assigned:2007-12-17
Published:2007-12-17
Updated:2017-08-08
Summary:Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-189
Vulnerability Consequences:Gain Access
References:Source: MISC
Type: UNKNOWN
http://bugs.gentoo.org/show_bug.cgi?id=202351

Source: MITRE
Type: CNA
CVE-2007-6353

Source: SUSE
Type: UNKNOWN
SUSE-SR:2008:001

Source: CCN
Type: SA28132
Exiv2 EXIF Parsing Integer Overflow Vulnerability

Source: SECUNIA
Type: Patch
28132

Source: SECUNIA
Type: UNKNOWN
28178

Source: SECUNIA
Type: UNKNOWN
28267

Source: SECUNIA
Type: UNKNOWN
28412

Source: SECUNIA
Type: UNKNOWN
28610

Source: SECUNIA
Type: UNKNOWN
32273

Source: GENTOO
Type: UNKNOWN
GLSA-200712-16

Source: DEBIAN
Type: UNKNOWN
DSA-1474

Source: DEBIAN
Type: DSA-1474
exiv2 -- integer overflow

Source: CCN
Type: Exiv2 Web site
Exiv2

Source: CCN
Type: GLSA-200712-16
Exiv2: Integer overflow

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2008:006

Source: CCN
Type: OSVDB ID: 40249
Exiv2 exif.cpp Crafted EXIF File Arbitrary Code Execution

Source: BID
Type: UNKNOWN
26918

Source: CCN
Type: BID-26918
Exiv2 EXIF File Handling Integer Overflow Vulnerability

Source: CCN
Type: USN-655-1
exiv2 vulnerabilities

Source: UBUNTU
Type: UNKNOWN
USN-655-1

Source: VUPEN
Type: UNKNOWN
ADV-2007-4252

Source: CCN
Type: Red Hat Bugzilla Bug 425921
CVE-2007-6353 exiv2: integer overflow in EXIF parsing

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=425921

Source: XF
Type: UNKNOWN
exiv2-setdataarea-bo(39118)

Source: XF
Type: UNKNOWN
exiv2-setdataarea-bo(39118)

Source: FEDORA
Type: UNKNOWN
FEDORA-2007-4591

Source: FEDORA
Type: UNKNOWN
FEDORA-2007-4551

Source: SUSE
Type: SUSE-SR:2008:001
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:exiv2:exiv2:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20076353
    V
    CVE-2007-6353
    2022-06-30
    oval:org.opensuse.security:def:42356
    P
    Security update for expat (Important)
    2022-03-15
    oval:org.opensuse.security:def:112209
    P
    exiv2-0.27.4-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:26217
    P
    Security update for java-1_7_1-ibm (Moderate) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:33109
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:42152
    P
    Security update for p11-kit (Important)
    2021-12-22
    oval:org.opensuse.security:def:31720
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:32236
    P
    Security update for MozillaFirefox (Important)
    2021-12-12
    oval:org.opensuse.security:def:26178
    P
    Security update for the Linux Kernel (Important)
    2021-12-02
    oval:org.opensuse.security:def:31299
    P
    Security update for qemu (Important)
    2021-11-10
    oval:org.opensuse.security:def:26160
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:105740
    P
    exiv2-0.27.4-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:31272
    P
    Security update for the Linux Kernel (Live Patch 40 for SLE 12 SP3) (Important)
    2021-09-23
    oval:org.opensuse.security:def:26129
    P
    Security update for gtk-vnc (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:32170
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:31667
    P
    Security update for fetchmail (Moderate)
    2021-08-18
    oval:org.opensuse.security:def:31664
    P
    Security update for cpio (Important)
    2021-08-14
    oval:org.opensuse.security:def:31663
    P
    Security update for djvulibre (Important)
    2021-08-05
    oval:org.opensuse.security:def:31225
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-07-21
    oval:org.opensuse.security:def:31651
    P
    Security update for libsolv (Important)
    2021-06-28
    oval:org.opensuse.security:def:31214
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:31213
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:32131
    P
    Security update for ovmf (Important)
    2021-06-22
    oval:org.opensuse.security:def:26076
    P
    Security update for webkit2gtk3 (Important)
    2021-06-17
    oval:org.opensuse.security:def:26072
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:26071
    P
    Security update for the Linux Kernel (Important)
    2021-06-09
    oval:org.opensuse.security:def:36446
    P
    libexiv2-4-32bit-0.17.1-31.20 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42592
    P
    libexiv2-4-0.17.1-31.20 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:31634
    P
    Security update for qemu (Important)
    2021-06-08
    oval:org.opensuse.security:def:36185
    P
    libexiv2-4-0.17.1-31.20 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32105
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:32913
    P
    Security update for samba (Important)
    2021-05-04
    oval:org.opensuse.security:def:32082
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:26028
    P
    Security update for xorg-x11-server (Important)
    2021-04-13
    oval:org.opensuse.security:def:31140
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:31364
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:31737
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:26199
    P
    Security update for ImageMagick (Moderate)
    2021-02-25
    oval:org.opensuse.security:def:32261
    P
    Security update for krb5-appl (Important)
    2021-02-19
    oval:org.opensuse.security:def:31726
    P
    Security update for the Linux Kernel (Important)
    2021-02-12
    oval:org.opensuse.security:def:31652
    P
    Security update for openssh (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:32192
    P
    Security update for java-1_8_0-ibm (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:32018
    P
    Security update for MozillaFirefox (Critical)
    2020-12-21
    oval:org.opensuse.security:def:25975
    P
    Security update for openssl-1_0_0 (Important)
    2020-12-09
    oval:org.opensuse.security:def:35586
    P
    libexiv2-4-0.17.1-31.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35745
    P
    libexiv2-4-0.17.1-31.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:41993
    P
    libexiv2-4-0.17.1-31.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35949
    P
    libexiv2-4-0.17.1-31.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:31417
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26280
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25926
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31989
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25138
    P
    Security update for dovecot22 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31431
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26311
    P
    Security update for openstack-nova and openstack-neutron (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32405
    P
    Security update for wavpack (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27444
    P
    libexiv2-4-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25499
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31502
    P
    Security update for python27 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26421
    P
    Security update for hdf5 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26014
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:32671
    P
    ghostscript-fonts-other on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25213
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31580
    P
    Security update for syslog-ng (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26413
    P
    Security update for go1.8 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32471
    P
    Security update for xorg-x11-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25511
    P
    Security update for ant (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31961
    P
    Security update for guile (Low)
    2020-12-01
    oval:org.opensuse.security:def:25996
    P
    Security update for libvirt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25581
    P
    Security update for perl-XML-Twig (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32026
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26466
    P
    Security update for irssi (Important)
    2020-12-01
    oval:org.opensuse.security:def:33148
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25938
    P
    Security update for evince (Important)
    2020-12-01
    oval:org.opensuse.security:def:31808
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26745
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25722
    P
    Security update for ovmf (Low)
    2020-12-01
    oval:org.opensuse.security:def:27148
    P
    ibutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25816
    P
    Security update for libqt4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31874
    P
    Security update for cyrus-imapd (Important)
    2020-12-01
    oval:org.opensuse.security:def:25297
    P
    Security update for libX11 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26572
    P
    kdelibs4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25869
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32551
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25734
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31508
    P
    Security update for python27 (Important)
    2020-12-01
    oval:org.opensuse.security:def:32874
    P
    gpg2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25372
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:31783
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26674
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26551
    P
    fvwm2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25746
    P
    Security update for openssl-1_1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25479
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31879
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26275
    P
    Security update for freerdp (Important)
    2020-12-01
    oval:org.opensuse.security:def:31055
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25784
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:26727
    P
    kdenetwork4-filesharing on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31416
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25714
    P
    Security update for libpng16 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31967
    P
    Security update for intel-SINIT (Important)
    2020-12-01
    oval:org.opensuse.security:def:26948
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25137
    P
    Security update for SDL (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25925
    P
    Security update for pcre (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32366
    P
    Security update for supportutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27409
    P
    gimp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31428
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26337
    P
    Security update for freexl (Low)
    2020-12-01
    oval:org.opensuse.security:def:32033
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25149
    P
    Security update for openssl-1_1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31523
    P
    Security update for rsync (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26364
    P
    Security update for irssi (Low)
    2020-12-01
    oval:org.opensuse.security:def:32427
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:25500
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31869
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32710
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25995
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25341
    P
    Security update for postgresql, postgresql96, postgresql10 and postgresql12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26452
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25575
    P
    Security update for libX11 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31769
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26710
    P
    gnome-screensaver on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26007
    P
    Security update for libid3tag (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25638
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26510
    P
    Security update for nextcloud (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26019
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25767
    P
    Security update for DirectFB (Important)
    2020-12-01
    oval:org.opensuse.security:def:31830
    P
    Security update for bind (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25873
    P
    Security update for libcares2 (Low)
    2020-12-01
    oval:org.opensuse.security:def:27183
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25296
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:25855
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:32512
    P
    freeradius-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31421
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25308
    P
    Security update for java-1_7_1-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26625
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25913
    P
    Security update for tcpdump, libpcap (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25735
    P
    Security update for exiv2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25422
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31823
    P
    Security update for bash (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26231
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31054
    P
    Security update for the Linux kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25703
    P
    Security update for squid (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31870
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:26713
    P
    gstreamer-0_10-plugins-base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26586
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25810
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25563
    P
    Security update for xrdp (Important)
    2020-12-01
    oval:org.opensuse.security:def:31928
    P
    Security update for giflib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26913
    P
    guestfs-data on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31066
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25841
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32317
    P
    Security update for rsync (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26771
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:17130
    P
    USN-655-1 -- exiv2 vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:7893
    P
    DSA-1474 exiv2 -- integer overflow
    2014-06-23
    oval:org.mitre.oval:def:20029
    P
    DSA-1474-1 exiv2 - arbitrary code execution
    2014-06-23
    oval:org.debian:def:1474
    V
    integer overflow
    2008-01-23
    BACK
    exiv2 exiv2 *