CVE-2006-4168Integer Overflow or Wraparound in Libexif

Severity
6.8MEDIUMNVD
EPSS
7.5%
top 8.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 14
Latest updateMay 1

Description

Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

Debianlibexif_project/libexif< 0.6.16-1+3
NVDlibexif/libexif6 versions+5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6mcf-v3q9-5w3p: Integer overflow in the exif_data_load_data_entry function in libexif/exif-data2022-05-01
CVEList
CVE-2006-4168: Integer overflow in the exif_data_load_data_entry function in libexif/exif-data2007-06-14
OSV
CVE-2006-4168: Integer overflow in the exif_data_load_data_entry function in libexif/exif-data2007-06-14

📋Vendor Advisories

3
Ubuntu
libexif vulnerability2007-06-27
Red Hat
libexif integer overflow2007-06-13
Debian
CVE-2006-4168: libexif - Integer overflow in the exif_data_load_data_entry function in libexif/exif-data....2006

💬Community

1
Bugzilla
CVE-2006-4168 libexif integer overflow2007-06-12
CVE-2006-4168 — Integer Overflow or Wraparound | cvebase