Description
libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in exif_loader.c.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9Confidentiality: None
Integrity: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-4j78-c8h2-ff3f: libexif 0↗2022-05-01 ▶ CVEListCVE-2007-6351: libexif 0↗2007-12-20 ▶ OSVCVE-2007-6351: libexif 0↗2007-12-20 ▶ 📋Vendor Advisories
3Ubuntulibexif vulnerabilities↗2008-10-14 ▶ Red Hatlibexif infinite recursion flaw (DoS)↗2007-12-14 ▶ DebianCVE-2007-6351: libexif - libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial ...↗2007 ▶ 💬Community
4BugzillaCVE-2007-6351 CVE-2007-6352 libexif various flaws [Fdevel]↗2007-12-14 ▶ BugzillaCVE-2007-6351 libexif infinite recursion flaw (DoS)↗2007-12-14 ▶ BugzillaCVE-2007-6351 CVE-2007-6352 libexif various flaws [F8]↗2007-12-14 ▶ BugzillaCVE-2007-6351 CVE-2007-6352 libexif various flaws [F7]↗2007-12-14 ▶