CVE-2008-2696
published 2008-06-13CVE-2008-2696: Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information…
PriorityP411medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.90%
77.4th percentile
Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong function.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | exiv2 | < exiv2 0.17-1 (bookworm) | exiv2 0.17-1 (bookworm) |
| exiv2 | exiv2 | — | — |
| exiv2 | exiv2 | >= 0 < 0.17-1 | 0.17-1 |
| exiv2 | exiv2 | >= 0 < 0.17-1 | 0.17-1 |
| exiv2 | exiv2 | >= 0 < 0.17-1 | 0.17-1 |
| exiv2 | exiv2 | >= 0 < 0.17-1 | 0.17-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rcfw-ggjf-vmfj: Exiv2 0
ghsa_unreviewed·2022-05-01
CVE-2008-2696 [MEDIUM] GHSA-rcfw-ggjf-vmfj: Exiv2 0
Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong function.
OSV
CVE-2008-2696: Exiv2 0
osv·2008-06-13·CVSS 4.3
CVE-2008-2696 [MEDIUM] CVE-2008-2696: Exiv2 0
Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong function.
Ubuntu
exiv2 vulnerabilities
vendor_ubuntu·2008-10-15·CVSS 7.5
CVE-2007-6353 [HIGH] exiv2 vulnerabilities
Title: exiv2 vulnerabilities
Summary: exiv2 vulnerabilities
Meder Kydyraliev discovered that exiv2 did not correctly handle certain
EXIF headers. If a user or automated system were tricked into processing
a specially crafted image, a remote attacker could cause the application
linked against libexiv2 to crash, leading to a denial of service, or
possibly executing arbitrary code with user privileges. (CVE-2007-6353)
Joakim Bildrulle discovered that exiv2 did not correctly handle Nikon
lens EXIF information. If a user or automated system were tricked into
processing a specially crafted image, a remote attacker could cause the
application linked against libexiv2 to crash, leading to a denial of
service. (CVE-2008-2696)
Instructions: After a standard system upgrade you need to restart your
Debian
CVE-2008-2696: exiv2 - Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (d...
vendor_debian·2008·CVSS 4.3
CVE-2008-2696 [MEDIUM] CVE-2008-2696: exiv2 - Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (d...
Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong function.
Scope: local
bookworm: resolved (fixed in 0.17-1)
bullseye: resolved (fixed in 0.17-1)
forky: resolved (fixed in 0.17-1)
sid: resolved (fixed in 0.17-1)
trixie: resolved (fixed in 0.17-1)
Red Hat
exiv2: crash / divide by zero on crafted images
vendor_redhat·CVSS 4.3
CVE-2008-2696 [MEDIUM] exiv2: crash / divide by zero on crafted images
exiv2: crash / divide by zero on crafted images
Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong function.
No detection rules found.
No public exploits indexed.
http://bugzilla.gnome.org/show_bug.cgi?id=524715http://dev.robotbattle.com/bugs/view.php?id=0000546http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00012.htmlhttp://secunia.com/advisories/30519http://secunia.com/advisories/32273http://www.exiv2.org/changelog.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:119http://www.securityfocus.com/bid/29586http://www.ubuntu.com/usn/usn-655-1http://www.vupen.com/english/advisories/2008/1766/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42885http://bugzilla.gnome.org/show_bug.cgi?id=524715http://dev.robotbattle.com/bugs/view.php?id=0000546http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00012.htmlhttp://secunia.com/advisories/30519http://secunia.com/advisories/32273http://www.exiv2.org/changelog.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:119http://www.securityfocus.com/bid/29586http://www.ubuntu.com/usn/usn-655-1http://www.vupen.com/english/advisories/2008/1766/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42885
2008-06-13
Published