Vulnerability Name: | CVE-2007-6355 (CCN-39141) | ||||||||||||||||
Assigned: | 2007-12-14 | ||||||||||||||||
Published: | 2007-12-14 | ||||||||||||||||
Updated: | 2011-05-13 | ||||||||||||||||
Summary: | Integer overflow in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6354. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-noinfo CWE-189 | ||||||||||||||||
Vulnerability Consequences: | Other | ||||||||||||||||
References: | Source: MISC Type: UNKNOWN http://bugs.gentoo.org/show_bug.cgi?id=202354 Source: MITRE Type: CNA CVE-2007-6354 Source: MITRE Type: CNA CVE-2007-6355 Source: CCN Type: exiftags Web page 20071215 version: exiftags 1.01 Source: CONFIRM Type: UNKNOWN http://johnst.org/sw/exiftags/CHANGES Source: CCN Type: SA28110 exiftags Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 28110 Source: SECUNIA Type: Vendor Advisory 28268 Source: SECUNIA Type: Vendor Advisory 29580 Source: GENTOO Type: UNKNOWN GLSA-200712-17 Source: DEBIAN Type: UNKNOWN DSA-1533 Source: DEBIAN Type: DSA-1533 exiftags -- insufficient input sanitizing Source: CCN Type: GLSA-200712-17 exiftags: Multiple vulnerabilities Source: CCN Type: OSVDB ID: 42646 exiftags Unspecified Field Offset Overflow #2 Source: CCN Type: OSVDB ID: 42648 exiftags Unspecified Field Offset Overflow #1 Source: BID Type: UNKNOWN 26892 Source: CCN Type: BID-26892 exiftags Multiple Unspecified Buffer Overflow And Denial Of Service Vulnerabilities Source: VUPEN Type: Vendor Advisory ADV-2007-4251 Source: XF Type: UNKNOWN exiftags-fieldoffset-multiple-unspecified(39141) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |