CVE-2007-6352
published 2007-12-20CVE-2007-6352: Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.73%
84.4th percentile
Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libexif | < libexif 0.6.16-2.1 (bookworm) | libexif 0.6.16-2.1 (bookworm) |
| libexif | libexif | <= 0.6.16 | — |
| libexif_project | libexif | >= 0 < 0.6.16-2.1 | 0.6.16-2.1 |
| libexif_project | libexif | >= 0 < 0.6.16-2.1 | 0.6.16-2.1 |
| libexif_project | libexif | >= 0 < 0.6.16-2.1 | 0.6.16-2.1 |
| libexif_project | libexif | >= 0 < 0.6.16-2.1 | 0.6.16-2.1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libexif vulnerabilities
vendor_ubuntu·2008-10-14
CVE-2007-6351 libexif vulnerabilities
Title: libexif vulnerabilities
Summary: libexif vulnerabilities
Meder Kydyraliev discovered that libexif did not correctly handle certain
EXIF headers. If a user or automated system were tricked into processing
a specially crafted image, a remote attacker could cause the application
linked against libexif to crash, leading to a denial of service, or
possibly executing arbitrary code with user privileges.
Instructions: After a standard system upgrade you need to restart your session to effect
the necessary changes.
Red Hat
libexif integer overflow
vendor_redhat·2007-12-14·CVSS 6.8
CVE-2007-6352 [MEDIUM] CWE-190 libexif integer overflow
libexif integer overflow
Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.
Debian
CVE-2007-6352: libexif - Integer overflow in libexif 0.6.16 and earlier allows context-dependent attacker...
vendor_debian·2007·CVSS 6.8
CVE-2007-6352 [MEDIUM] CVE-2007-6352: libexif - Integer overflow in libexif 0.6.16 and earlier allows context-dependent attacker...
Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.
Scope: local
bookworm: resolved (fixed in 0.6.16-2.1)
bullseye: resolved (fixed in 0.6.16-2.1)
forky: resolved (fixed in 0.6.16-2.1)
sid: resolved (fixed in 0.6.16-2.1)
trixie: resolved (fixed in 0.6.16-2.1)
GHSA
GHSA-wpmg-rx8c-q5g8: Integer overflow in libexif 0
ghsa_unreviewed·2022-05-01
CVE-2007-6352 [MEDIUM] GHSA-wpmg-rx8c-q5g8: Integer overflow in libexif 0
Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.
OSV
CVE-2007-6352: Integer overflow in libexif 0
osv·2007-12-20·CVSS 6.8
CVE-2007-6352 [MEDIUM] CVE-2007-6352: Integer overflow in libexif 0
Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.
No detection rules found.
Bugzilla
CVE-2007-6351 CVE-2007-6352 libexif various flaws [Fdevel]
bugzilla·2007-12-14·CVSS 4.3
CVE-2007-6351 [MEDIUM] CVE-2007-6351 CVE-2007-6352 libexif various flaws [Fdevel]
CVE-2007-6351 CVE-2007-6352 libexif various flaws [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2007-6351 CVE-2007-6352 libexif various flaws [F8]
bugzilla·2007-12-14·CVSS 4.3
CVE-2007-6351 [MEDIUM] CVE-2007-6351 CVE-2007-6352 libexif various flaws [F8]
CVE-2007-6351 CVE-2007-6352 libexif various flaws [F8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
libexif-0.6.15-5.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-6352 libexif integer overflow
bugzilla·2007-12-14·CVSS 6.8
CVE-2007-6352 [MEDIUM] CVE-2007-6352 libexif integer overflow
CVE-2007-6352 libexif integer overflow
An integer overflow flaw was found in libexif. This flaw could be leveraged by
an attacker to execute arbitrary code withe the permissions of the application
parsing the EXIF image data.
Discussion:
Created attachment 289541
Upstream patch
---
Fixed in affected Red Hat Enterprise Linux versions:
http://rhn.redhat.com/errata/RHSA-2007-1165.html
http://rhn.redhat.com/errata/RHSA-2007-1166.html
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2007-1165.html
http://rhn.redhat.com/errata/RHSA-2007-1166.html
Fedora:
https://admin.fedoraproject.org/updates/F7/FEDORA-2007-4608
https://admin.fedoraproject.org/updates/F8/FEDORA-2007-4667
Bugzilla
CVE-2007-6351 CVE-2007-6352 libexif various flaws [F7]
bugzilla·2007-12-14·CVSS 4.3
CVE-2007-6351 [MEDIUM] CVE-2007-6351 CVE-2007-6352 libexif various flaws [F7]
CVE-2007-6351 CVE-2007-6352 libexif various flaws [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
libexif-0.6.15-3.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
http://bugs.gentoo.org/show_bug.cgi?id=202350http://osvdb.org/42653http://secunia.com/advisories/28076http://secunia.com/advisories/28127http://secunia.com/advisories/28195http://secunia.com/advisories/28266http://secunia.com/advisories/28346http://secunia.com/advisories/28400http://secunia.com/advisories/28636http://secunia.com/advisories/28776http://secunia.com/advisories/29381http://secunia.com/advisories/32274http://security.gentoo.org/glsa/glsa-200712-15.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-234701-1http://www.debian.org/security/2008/dsa-1487http://www.mandriva.com/security/advisories?name=MDVSA-2008:005http://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1165.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1166.htmlhttp://www.securityfocus.com/archive/1/485822/100/0/threadedhttp://www.securityfocus.com/bid/26942http://www.securitytracker.com/id?1019124http://www.ubuntu.com/usn/usn-654-1http://www.vupen.com/english/advisories/2007/4278http://www.vupen.com/english/advisories/2008/0947/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=425561https://bugzilla.redhat.com/show_bug.cgi?id=425621https://bugzilla.redhat.com/show_bug.cgi?id=425631https://exchange.xforce.ibmcloud.com/vulnerabilities/39167https://issues.rpath.com/browse/RPL-2068https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11029https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4814https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00597.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00626.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=202350http://osvdb.org/42653http://secunia.com/advisories/28076http://secunia.com/advisories/28127http://secunia.com/advisories/28195http://secunia.com/advisories/28266http://secunia.com/advisories/28346http://secunia.com/advisories/28400http://secunia.com/advisories/28636http://secunia.com/advisories/28776http://secunia.com/advisories/29381http://secunia.com/advisories/32274http://security.gentoo.org/glsa/glsa-200712-15.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-234701-1http://www.debian.org/security/2008/dsa-1487http://www.mandriva.com/security/advisories?name=MDVSA-2008:005http://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1165.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1166.htmlhttp://www.securityfocus.com/archive/1/485822/100/0/threadedhttp://www.securityfocus.com/bid/26942http://www.securitytracker.com/id?1019124http://www.ubuntu.com/usn/usn-654-1http://www.vupen.com/english/advisories/2007/4278http://www.vupen.com/english/advisories/2008/0947/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=425561https://bugzilla.redhat.com/show_bug.cgi?id=425621https://bugzilla.redhat.com/show_bug.cgi?id=425631https://exchange.xforce.ibmcloud.com/vulnerabilities/39167https://issues.rpath.com/browse/RPL-2068https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11029https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4814https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00597.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00626.html
2007-12-20
Published