CVE-2012-2837
published 2012-07-13CVE-2012-2837: The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.86%
89.0th percentile
The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libexif | < libexif 0.6.20-3 (bookworm) | libexif 0.6.20-3 (bookworm) |
| libexif_project | libexif | <= 0.6.20 | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libexif vulnerabilities
vendor_ubuntu·2012-07-23·CVSS 6.4
CVE-2012-2812 [MEDIUM] libexif vulnerabilities
Title: libexif vulnerabilities
Summary: libexif could be made to crash, run programs as your login, or expose
sensitive information if it opened a specially crafted file.
Mateusz Jurczyk discovered that libexif incorrectly parsed certain
malformed EXIF tags. If a user or automated system were tricked into
processing a specially crafted image file, an attacker could cause libexif
to crash, leading to a denial of service, or possibly obtain sensitive
information. (CVE-2012-2812, CVE-2012-2813)
Mateusz Jurczyk discovered that libexif incorrectly parsed certain
malformed EXIF tags. If a user or automated system were tricked into
processing a specially crafted image file, an attacker could cause libexif
to crash, leading to a denial of service, or possibly execute arbitrary
code. (CVE-2012-2
Red Hat
libexif: "mnote_olympus_entry_get_value()" division by zero
vendor_redhat·2012-07-12·CVSS 5.0
CVE-2012-2837 [MEDIUM] libexif: "mnote_olympus_entry_get_value()" division by zero
libexif: "mnote_olympus_entry_get_value()" division by zero
The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags.
Debian
CVE-2012-2837: libexif - The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in t...
vendor_debian·2012·CVSS 5.0
CVE-2012-2837 [MEDIUM] CVE-2012-2837: libexif - The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in t...
The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags.
Scope: local
bookworm: resolved (fixed in 0.6.20-3)
bullseye: resolved (fixed in 0.6.20-3)
forky: resolved (fixed in 0.6.20-3)
sid: resolved (fixed in 0.6.20-3)
trixie: resolved (fixed in 0.6.20-3)
GHSA
GHSA-365p-hvj9-f68w: The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry
ghsa_unreviewed·2022-05-13
CVE-2012-2837 [MEDIUM] GHSA-365p-hvj9-f68w: The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry
The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags.
OSV
CVE-2012-2837: The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry
osv·2012-07-13·CVSS 5.0
CVE-2012-2837 [MEDIUM] CVE-2012-2837: The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry
The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2812 libexif various flaws [fedora-all]
bugzilla·2012-07-13·CVSS 6.4
CVE-2012-2813 [MEDIUM] CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2812 libexif various flaws [fedora-all]
CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2812 libexif various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
ht
Bugzilla
CVE-2012-2837 libexif: "mnote_olympus_entry_get_value()" division by zero
bugzilla·2012-07-11·CVSS 5.0
CVE-2012-2837 [MEDIUM] CVE-2012-2837 libexif: "mnote_olympus_entry_get_value()" division by zero
CVE-2012-2837 libexif: "mnote_olympus_entry_get_value()" division by zero
A divide-by-zero error in the mnote_olympus_entry_get_value function while formatting EXIF maker note tags in libexif 0.6.20 and earlier allows remote attackers to cause a denial of service via an image with crafted EXIF tags.
Discussion:
This now public via exif 0.6.21:
http://libexif.cvs.sourceforge.net/viewvc/libexif/libexif/ChangeLog?revision=1.370
http://libexif.cvs.sourceforge.net/viewvc/libexif/libexif/libexif/olympus/mnote-olympus-entry.c?r1=1.54&r2=1.55&view=patch
---
Created libexif tracking bugs for this issue
Affects: fedora-all [bug 839917]
---
Upstream bug:
http://sourceforge.net/tracker/?func=detail&aid=3434545&group_id=12272&atid=112272
---
Upstream advisory:
http://sourceforge.net/mailarch
Bugzilla
libexif security vulnerabilities
bugzilla·2012-07-05·CVSS 6.4
[MEDIUM] libexif security vulnerabilities
libexif security vulnerabilities
libexif ver. 0.6.20 and earlier suffers from a number of newly-discovered security vulnerabilities. The details will be made public with a new release of libexif that fixes them, which is planned to be the second week of July.
Very little has changed since version 0.6.20, so the new version should be a drop-in replacement. But, if you're interested in some advance testing, a prerelease version (that does NOT contain the security patches) is available at
http://sourceforge.net/projects/libexif/files/libexif/prerelease/libexif-0.6.21-pre1.tar.gz/download This prerelease should otherwise be substantially similar to the final release.
I'll update this bug with CVE numbers and more details before the release.
Discussion:
These are the CVEs fixed in version
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1255.htmlhttp://secunia.com/advisories/49988http://sourceforge.net/mailarchive/message.php?msg_id=29534027http://www.debian.org/security/2012/dsa-2559http://www.securityfocus.com/bid/54437http://www.ubuntu.com/usn/USN-1513-1http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1255.htmlhttp://secunia.com/advisories/49988http://sourceforge.net/mailarchive/message.php?msg_id=29534027http://www.debian.org/security/2012/dsa-2559http://www.securityfocus.com/bid/54437http://www.ubuntu.com/usn/USN-1513-1
2012-07-13
Published