CVE-2005-0664
published 2005-05-02CVE-2005-0664: Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial…
PriorityP422low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
4.46%
90.4th percentile
Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libexif | < libexif 0.6.9-5 (bookworm) | libexif 0.6.9-5 (bookworm) |
| libexif | libexif | — | — |
| libexif_project | libexif | >= 0 < 0.6.9-5 | 0.6.9-5 |
| libexif_project | libexif | >= 0 < 0.6.9-5 | 0.6.9-5 |
| libexif_project | libexif | >= 0 < 0.6.9-5 | 0.6.9-5 |
| libexif_project | libexif | >= 0 < 0.6.9-5 | 0.6.9-5 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gvww-3fhc-2r58: Buffer overflow in the EXIF library (libexif) 0
ghsa_unreviewed·2022-05-01
CVE-2005-0664 [LOW] GHSA-gvww-3fhc-2r58: Buffer overflow in the EXIF library (libexif) 0
Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag.
OSV
CVE-2005-0664: Buffer overflow in the EXIF library (libexif) 0
osv·2005-05-02·CVSS 2.6
CVE-2005-0664 [LOW] CVE-2005-0664: Buffer overflow in the EXIF library (libexif) 0
Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag.
Debian
CVE-2005-0664: libexif - Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate t...
vendor_debian·2005·CVSS 2.6
CVE-2005-0664 [LOW] CVE-2005-0664: libexif - Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate t...
Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag.
Scope: local
bookworm: resolved (fixed in 0.6.9-5)
bullseye: resolved (fixed in 0.6.9-5)
forky: resolved (fixed in 0.6.9-5)
sid: resolved (fixed in 0.6.9-5)
trixie: resolved (fixed in 0.6.9-5)
Red Hat
security flaw
vendor_redhat·2004-03-03·CVSS 2.6
CVE-2005-0664 [LOW] security flaw
security flaw
Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/17705http://securitytracker.com/id?1013398http://sunsolve.sun.com/search/document.do?assetkey=1-26-102041-1http://www.debian.org/security/2005/dsa-709http://www.gentoo.org/security/en/glsa/glsa-200503-17.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:064http://www.redhat.com/support/errata/RHSA-2005-300.htmlhttp://www.vupen.com/english/advisories/2005/0240http://www.vupen.com/english/advisories/2005/2565https://bugzilla.ubuntu.com/show_bug.cgi?id=7152https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10832https://usn.ubuntu.com/91-1/http://secunia.com/advisories/17705http://securitytracker.com/id?1013398http://sunsolve.sun.com/search/document.do?assetkey=1-26-102041-1http://www.debian.org/security/2005/dsa-709http://www.gentoo.org/security/en/glsa/glsa-200503-17.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:064http://www.redhat.com/support/errata/RHSA-2005-300.htmlhttp://www.vupen.com/english/advisories/2005/0240http://www.vupen.com/english/advisories/2005/2565https://bugzilla.ubuntu.com/show_bug.cgi?id=7152https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10832https://usn.ubuntu.com/91-1/
2005-05-02
Published