CVE-2012-2813
published 2012-07-13CVE-2012-2813: The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial…
PriorityP427medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
3.77%
88.7th percentile
The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libexif | < libexif 0.6.20-3 (bookworm) | libexif 0.6.20-3 (bookworm) |
| libexif_project | libexif | <= 0.6.20 | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libexif vulnerabilities
vendor_ubuntu·2012-07-23·CVSS 6.4
CVE-2012-2812 [MEDIUM] libexif vulnerabilities
Title: libexif vulnerabilities
Summary: libexif could be made to crash, run programs as your login, or expose
sensitive information if it opened a specially crafted file.
Mateusz Jurczyk discovered that libexif incorrectly parsed certain
malformed EXIF tags. If a user or automated system were tricked into
processing a specially crafted image file, an attacker could cause libexif
to crash, leading to a denial of service, or possibly obtain sensitive
information. (CVE-2012-2812, CVE-2012-2813)
Mateusz Jurczyk discovered that libexif incorrectly parsed certain
malformed EXIF tags. If a user or automated system were tricked into
processing a specially crafted image file, an attacker could cause libexif
to crash, leading to a denial of service, or possibly execute arbitrary
code. (CVE-2012-2
Red Hat
libexif: "exif_convert_utf16_to_utf8()" heap-based out-of-bounds array read
vendor_redhat·2012-07-12·CVSS 6.4
CVE-2012-2813 [MEDIUM] libexif: "exif_convert_utf16_to_utf8()" heap-based out-of-bounds array read
libexif: "exif_convert_utf16_to_utf8()" heap-based out-of-bounds array read
The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.
Red Hat
squirrelmail: not fixed in RHSA-2012:0103
vendor_redhat·2012-04-20·CVSS 5.0
CVE-2012-2124 [MEDIUM] squirrelmail: not fixed in RHSA-2012:0103
squirrelmail: not fixed in RHSA-2012:0103
functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preference files. NOTE: this issue exists because of an incorrect fix for CVE-2010-2813.
Package: squirrelmail (Red Hat Enterprise Linux 4) - Will not fix
Debian
CVE-2012-2813: libexif - The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing ...
vendor_debian·2012·CVSS 6.4
CVE-2012-2813 [MEDIUM] CVE-2012-2813: libexif - The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing ...
The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.
Scope: local
bookworm: resolved (fixed in 0.6.20-3)
bullseye: resolved (fixed in 0.6.20-3)
forky: resolved (fixed in 0.6.20-3)
sid: resolved (fixed in 0.6.20-3)
trixie: resolved (fixed in 0.6.20-3)
GHSA
GHSA-hvfw-p9q6-r9hp: The exif_convert_utf16_to_utf8 function in exif-entry
ghsa_unreviewed·2022-05-13
CVE-2012-2813 [MEDIUM] CWE-119 GHSA-hvfw-p9q6-r9hp: The exif_convert_utf16_to_utf8 function in exif-entry
The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.
OSV
CVE-2012-2813: The exif_convert_utf16_to_utf8 function in exif-entry
osv·2012-07-13·CVSS 6.4
CVE-2012-2813 [MEDIUM] CVE-2012-2813: The exif_convert_utf16_to_utf8 function in exif-entry
The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2812 libexif various flaws [fedora-all]
bugzilla·2012-07-13·CVSS 6.4
CVE-2012-2813 [MEDIUM] CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2812 libexif various flaws [fedora-all]
CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2812 libexif various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
ht
Bugzilla
CVE-2012-2813 libexif: "exif_convert_utf16_to_utf8()" heap-based out-of-bounds array read
bugzilla·2012-07-11·CVSS 6.4
CVE-2012-2813 [MEDIUM] CVE-2012-2813 libexif: "exif_convert_utf16_to_utf8()" heap-based out-of-bounds array read
CVE-2012-2813 libexif: "exif_convert_utf16_to_utf8()" heap-based out-of-bounds array read
A heap-based out-of-bounds array read in the function in libexif/exif-entry.c in libexif 0.6.20 and earlier allows remote attackers to cause a denial of service or possibly obtain potentially sensitive information from process memory via an image with crafted EXIF tags.
Discussion:
This now public via exif 0.6.21:
http://libexif.cvs.sourceforge.net/viewvc/libexif/libexif/ChangeLog?revision=1.370
http://libexif.cvs.sourceforge.net/viewvc/libexif/libexif/libexif/exif-entry.c?r1=1.146&r2=1.147&view=patch
---
Created libexif tracking bugs for this issue
Affects: fedora-all [bug 839917]
---
Upstream advisory:
http://sourceforge.net/mailarchive/message.php?msg_id=29534027
---
Acknowledgements:
R
Bugzilla
libexif security vulnerabilities
bugzilla·2012-07-05·CVSS 6.4
[MEDIUM] libexif security vulnerabilities
libexif security vulnerabilities
libexif ver. 0.6.20 and earlier suffers from a number of newly-discovered security vulnerabilities. The details will be made public with a new release of libexif that fixes them, which is planned to be the second week of July.
Very little has changed since version 0.6.20, so the new version should be a drop-in replacement. But, if you're interested in some advance testing, a prerelease version (that does NOT contain the security patches) is available at
http://sourceforge.net/projects/libexif/files/libexif/prerelease/libexif-0.6.21-pre1.tar.gz/download This prerelease should otherwise be substantially similar to the final release.
I'll update this bug with CVE numbers and more details before the release.
Discussion:
These are the CVEs fixed in version
Bugzilla
CVE-2012-2124 squirrelmail: CVE-2010-2813 not fixed in RHSA-2012:0103
bugzilla·2012-04-20·CVSS 5.0
CVE-2012-2124 [MEDIUM] CVE-2012-2124 squirrelmail: CVE-2010-2813 not fixed in RHSA-2012:0103
CVE-2012-2124 squirrelmail: CVE-2010-2813 not fixed in RHSA-2012:0103
A Red Hat Security Advisory RHSA-2012:0103 for squirrelmail packages shipped in Red Hat Enterprise Linux 4 and 5 claim to have fixed CVE-2010-2813 issue ("CVE-2010-2813 SquirrelMail: DoS (disk space consumption) by random IMAP login attempts with 8-bit characters in the password", bug #618096). However, the patch for this issue was not applied correctly and hence the issue was not fixed as stated in the advisory.
Discussion:
CVE assignment notification:
http://www.openwall.com/lists/oss-security/2012/04/20/22
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0126 https://rhn.redhat.com/errata/RHSA-2013-0126.html
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1255.htmlhttp://secunia.com/advisories/49988http://sourceforge.net/mailarchive/message.php?msg_id=29534027http://www.debian.org/security/2012/dsa-2559http://www.securityfocus.com/bid/54437http://www.ubuntu.com/usn/USN-1513-1http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1255.htmlhttp://secunia.com/advisories/49988http://sourceforge.net/mailarchive/message.php?msg_id=29534027http://www.debian.org/security/2012/dsa-2559http://www.securityfocus.com/bid/54437http://www.ubuntu.com/usn/USN-1513-1
2012-07-13
Published