Description
Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4 Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-wpmg-rx8c-q5g8: Integer overflow in libexif 0↗2022-05-01 ▶ CVEListCVE-2007-6352: Integer overflow in libexif 0↗2007-12-20 ▶ OSVCVE-2007-6352: Integer overflow in libexif 0↗2007-12-20 ▶ 💥Exploits & PoCs
1Exploit-DBMicrosoft Office 2007/2010 - OLE Arbitrary Command Execution↗2014-11-12 ▶ 📋Vendor Advisories
3Ubuntulibexif vulnerabilities↗2008-10-14 ▶ Red Hatlibexif integer overflow↗2007-12-14 ▶ DebianCVE-2007-6352: libexif - Integer overflow in libexif 0.6.16 and earlier allows context-dependent attacker...↗2007 ▶ 💬Community
4BugzillaCVE-2007-6351 CVE-2007-6352 libexif various flaws [Fdevel]↗2007-12-14 ▶ BugzillaCVE-2007-6351 CVE-2007-6352 libexif various flaws [F8]↗2007-12-14 ▶ BugzillaCVE-2007-6352 libexif integer overflow↗2007-12-14 ▶ BugzillaCVE-2007-6351 CVE-2007-6352 libexif various flaws [F7]↗2007-12-14 ▶