CVE-2009-3895
published 2009-11-20CVE-2009-3895: Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.12%
91.4th percentile
Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via an invalid EXIF image. NOTE: some of these details are obtained from third party information.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libexif | < libexif 0.6.19-1 (bookworm) | libexif 0.6.19-1 (bookworm) |
| libexif_project | libexif | — | — |
| libexif_project | libexif | >= 0 < 0.6.19-1 | 0.6.19-1 |
| libexif_project | libexif | >= 0 < 0.6.19-1 | 0.6.19-1 |
| libexif_project | libexif | >= 0 < 0.6.19-1 | 0.6.19-1 |
| libexif_project | libexif | >= 0 < 0.6.19-1 | 0.6.19-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v836-r6h4-7334: Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry
ghsa_unreviewed·2022-05-02
CVE-2009-3895 [MEDIUM] CWE-119 GHSA-v836-r6h4-7334: Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry
Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via an invalid EXIF image. NOTE: some of these details are obtained from third party information.
OSV
CVE-2009-3895: Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry
osv·2009-11-20·CVSS 6.8
CVE-2009-3895 [MEDIUM] CVE-2009-3895: Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry
Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via an invalid EXIF image. NOTE: some of these details are obtained from third party information.
Debian
CVE-2009-3895: libexif - Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup rou...
vendor_debian·2009·CVSS 6.8
CVE-2009-3895 [MEDIUM] CVE-2009-3895: libexif - Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup rou...
Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via an invalid EXIF image. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 0.6.19-1)
bullseye: resolved (fixed in 0.6.19-1)
forky: resolved (fixed in 0.6.19-1)
sid: resolved (fixed in 0.6.19-1)
trixie: resolved (fixed in 0.6.19-1)
Red Hat
CVE-2009-3895: Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry
vendor_redhat·CVSS 6.8
CVE-2009-3895 [MEDIUM] CVE-2009-3895: Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry
Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via an invalid EXIF image. NOTE: some of these details are obtained from third party information.
Statement: Not vulnerable. This issue did not affect the versions of libexif as shipped with Red Hat Enterprise Linux 4, or 5.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.debian.org/557137http://bugs.gentoo.org/show_bug.cgi?id=293190http://libexif.cvs.sourceforge.net/viewvc/libexif/libexif/NEWS?view=markup&pathrev=libexif-0_6_19-releasehttp://secunia.com/advisories/37378http://sourceforge.net/mailarchive/message.php?msg_name=20091113072359.GA22681%40coneharvesters.comhttp://www.openwall.com/lists/oss-security/2009/11/19/2http://www.osvdb.org/59956http://www.securityfocus.com/bid/37022http://www.vupen.com/english/advisories/2009/3243https://exchange.xforce.ibmcloud.com/vulnerabilities/54275http://bugs.debian.org/557137http://bugs.gentoo.org/show_bug.cgi?id=293190http://libexif.cvs.sourceforge.net/viewvc/libexif/libexif/NEWS?view=markup&pathrev=libexif-0_6_19-releasehttp://secunia.com/advisories/37378http://sourceforge.net/mailarchive/message.php?msg_name=20091113072359.GA22681%40coneharvesters.comhttp://www.openwall.com/lists/oss-security/2009/11/19/2http://www.osvdb.org/59956http://www.securityfocus.com/bid/37022http://www.vupen.com/english/advisories/2009/3243https://exchange.xforce.ibmcloud.com/vulnerabilities/54275
2009-11-20
Published