CVE-2007-6353
published 2007-12-20CVE-2007-6353: Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.87%
91.1th percentile
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | exiv2 | < exiv2 0.15-2 (bookworm) | exiv2 0.15-2 (bookworm) |
| exiv2 | exiv2 | < 0.16 | 0.16 |
| exiv2 | exiv2 | >= 0 < 0.15-2 | 0.15-2 |
| exiv2 | exiv2 | >= 0 < 0.15-2 | 0.15-2 |
| exiv2 | exiv2 | >= 0 < 0.15-2 | 0.15-2 |
| exiv2 | exiv2 | >= 0 < 0.15-2 | 0.15-2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
exiv2 vulnerabilities
vendor_ubuntu·2008-10-15·CVSS 7.5
CVE-2007-6353 [HIGH] exiv2 vulnerabilities
Title: exiv2 vulnerabilities
Summary: exiv2 vulnerabilities
Meder Kydyraliev discovered that exiv2 did not correctly handle certain
EXIF headers. If a user or automated system were tricked into processing
a specially crafted image, a remote attacker could cause the application
linked against libexiv2 to crash, leading to a denial of service, or
possibly executing arbitrary code with user privileges. (CVE-2007-6353)
Joakim Bildrulle discovered that exiv2 did not correctly handle Nikon
lens EXIF information. If a user or automated system were tricked into
processing a specially crafted image, a remote attacker could cause the
application linked against libexiv2 to crash, leading to a denial of
service. (CVE-2008-2696)
Instructions: After a standard system upgrade you need to restart your
Debian
CVE-2007-6353: exiv2 - Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers...
vendor_debian·2007·CVSS 7.5
CVE-2007-6353 [HIGH] CVE-2007-6353: exiv2 - Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers...
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.15-2)
bullseye: resolved (fixed in 0.15-2)
forky: resolved (fixed in 0.15-2)
sid: resolved (fixed in 0.15-2)
trixie: resolved (fixed in 0.15-2)
Red Hat
exiv2: integer overflow in EXIF parsing
vendor_redhat·CVSS 7.5
CVE-2007-6353 [HIGH] exiv2: integer overflow in EXIF parsing
exiv2: integer overflow in EXIF parsing
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
GHSA
GHSA-g589-q56x-4rhp: Integer overflow in exif
ghsa_unreviewed·2022-05-01
CVE-2007-6353 [HIGH] CWE-190 GHSA-g589-q56x-4rhp: Integer overflow in exif
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
OSV
CVE-2007-6353: Integer overflow in exif
osv·2007-12-20·CVSS 7.5
CVE-2007-6353 [HIGH] CVE-2007-6353: Integer overflow in exif
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-6353 exiv2: integer overflow in EXIF parsing
bugzilla·2007-12-17·CVSS 7.5
CVE-2007-6353 [HIGH] CVE-2007-6353 exiv2: integer overflow in EXIF parsing
CVE-2007-6353 exiv2: integer overflow in EXIF parsing
Meder Kydyraliev reported an integer overflow exiv2's EXIF parsing code
resulting in heap buffer oveflow. This can possibly lead to code execution as
user running application using exiv2 library to extract EXIF tags from
malicious image files.
Upstream commit:
http://dev.robotbattle.com/~cvsuser/cgi-bin/ns_viewcvs.cgi/exiv2/trunk/src/exif.cpp?rev=1346&r1=1231&r2=1346
Discussion:
This is (apparently, can't see it yet), the upstream issue tracker:
http://dev.robotbattle.com/bugs/view.php?id=534
---
(In reply to comment #1)
> http://dev.robotbattle.com/bugs/view.php?id=534
Yes it is. That report was first opened as public and it also contained further
details about similar problems in other EXIF parsing libraries (see e.g. our
bugs
Bugzilla
CVE-2007-6353 exiv2: integer overflow in EXIF parsing [EPEL-5]
bugzilla·2007-12-17·CVSS 7.5
CVE-2007-6353 [HIGH] CVE-2007-6353 exiv2: integer overflow in EXIF parsing [EPEL-5]
CVE-2007-6353 exiv2: integer overflow in EXIF parsing [EPEL-5]
+++ This bug was initially created as a clone of Bug #425922 +++
This is an automatically created tracking bug!
It was created to ensure that one or more security vulnerabilities are fixed in
all affected releases. You should not refer to it anywhere except in the update
system as it is a private "Fedora Project Contributors" bug. The update system
should close this bug it once the update is pushed.
For comments that are specific to a vulnerability please use bugs filed against
"Security Response" product referenced in "Blocks" field.
bug #425921: CVE-2007-6353 exiv2: integer overflow in EXIF parsing
When creating an update for the version this this bug is reported against please
include the bug IDs of respective bugs fil
Bugzilla
CVE-2007-6353 exiv2: integer overflow in EXIF parsing [EPEL-4]
bugzilla·2007-12-17·CVSS 7.5
CVE-2007-6353 [HIGH] CVE-2007-6353 exiv2: integer overflow in EXIF parsing [EPEL-4]
CVE-2007-6353 exiv2: integer overflow in EXIF parsing [EPEL-4]
+++ This bug was initially created as a clone of Bug #425993 +++
This is an automatically created tracking bug!
It was created to ensure that one or more security vulnerabilities are fixed in
all affected releases. You should not refer to it anywhere except in the update
system as it is a private "Fedora Project Contributors" bug. The update system
should close this bug it once the update is pushed.
For comments that are specific to a vulnerability please use bugs filed against
"Security Response" product referenced in "Blocks" field.
bug #425921: CVE-2007-6353 exiv2: integer overflow in EXIF parsing
When creating an update for the version this this bug is reported against please
include the bug IDs of respective bugs fil
Bugzilla
CVE-2007-2953 vim format string flaw
bugzilla·2007-07-17·CVSS 6.8
CVE-2007-2953 [MEDIUM] CVE-2007-2953 vim format string flaw
CVE-2007-2953 vim format string flaw
Secunia Research has discovered a vulnerability in Vim, which can be
exploited by malicious people to compromise a vulnerable system.
Vulnerability details:
A format string error in the "helptags_one()" function in src/ex_cmds.c
when running the "helptags" command can be exploited to execute
arbitrary code via specially crafted help files. The "helptags" command
creates a tag file from tags surrounded by asterisks in help files, and
the part of the code that handles tags starting with the string "help-
tags" is incorrect, leading to this vulnerability.
The offending code in src/ex_cmds.c looks like this, starting from line
6353:
s = ((char_u **)ga.ga_data)[i];
if (STRNCMP(s, "help-tags", 9) == 0)
/* help-tags entry was added in formatted form */
f
http://bugs.gentoo.org/show_bug.cgi?id=202351http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.htmlhttp://secunia.com/advisories/28132http://secunia.com/advisories/28178http://secunia.com/advisories/28267http://secunia.com/advisories/28412http://secunia.com/advisories/28610http://secunia.com/advisories/32273http://security.gentoo.org/glsa/glsa-200712-16.xmlhttp://www.debian.org/security/2008/dsa-1474http://www.mandriva.com/security/advisories?name=MDVSA-2008:006http://www.securityfocus.com/bid/26918http://www.ubuntu.com/usn/usn-655-1http://www.vupen.com/english/advisories/2007/4252https://bugzilla.redhat.com/show_bug.cgi?id=425921https://exchange.xforce.ibmcloud.com/vulnerabilities/39118https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00652.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00674.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=202351http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.htmlhttp://secunia.com/advisories/28132http://secunia.com/advisories/28178http://secunia.com/advisories/28267http://secunia.com/advisories/28412http://secunia.com/advisories/28610http://secunia.com/advisories/32273http://security.gentoo.org/glsa/glsa-200712-16.xmlhttp://www.debian.org/security/2008/dsa-1474http://www.mandriva.com/security/advisories?name=MDVSA-2008:006http://www.securityfocus.com/bid/26918http://www.ubuntu.com/usn/usn-655-1http://www.vupen.com/english/advisories/2007/4252https://bugzilla.redhat.com/show_bug.cgi?id=425921https://exchange.xforce.ibmcloud.com/vulnerabilities/39118https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00652.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00674.html
2007-12-20
Published