CVE-2012-2840
published 2012-07-13CVE-2012-2840: Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.02%
91.3th percentile
Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted EXIF tags in an image.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libexif | < libexif 0.6.20-3 (bookworm) | libexif 0.6.20-3 (bookworm) |
| libexif_project | libexif | <= 0.6.20 | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | — | — |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7r47-9m3f-8mp5: Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry
ghsa_unreviewed·2022-05-13
CVE-2012-2840 [HIGH] GHSA-7r47-9m3f-8mp5: Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry
Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted EXIF tags in an image.
OSV
CVE-2012-2840: Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry
osv·2012-07-13·CVSS 7.5
CVE-2012-2840 [HIGH] CVE-2012-2840: Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry
Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted EXIF tags in an image.
Ubuntu
libexif vulnerabilities
vendor_ubuntu·2012-07-23·CVSS 6.4
CVE-2012-2812 [MEDIUM] libexif vulnerabilities
Title: libexif vulnerabilities
Summary: libexif could be made to crash, run programs as your login, or expose
sensitive information if it opened a specially crafted file.
Mateusz Jurczyk discovered that libexif incorrectly parsed certain
malformed EXIF tags. If a user or automated system were tricked into
processing a specially crafted image file, an attacker could cause libexif
to crash, leading to a denial of service, or possibly obtain sensitive
information. (CVE-2012-2812, CVE-2012-2813)
Mateusz Jurczyk discovered that libexif incorrectly parsed certain
malformed EXIF tags. If a user or automated system were tricked into
processing a specially crafted image file, an attacker could cause libexif
to crash, leading to a denial of service, or possibly execute arbitrary
code. (CVE-2012-2
Red Hat
libexif: "exif_convert_utf16_to_utf8()" off-by-one
vendor_redhat·2012-07-12·CVSS 7.5
CVE-2012-2840 [HIGH] CWE-193 libexif: "exif_convert_utf16_to_utf8()" off-by-one
libexif: "exif_convert_utf16_to_utf8()" off-by-one
Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted EXIF tags in an image.
Debian
CVE-2012-2840: libexif - Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in t...
vendor_debian·2012·CVSS 7.5
CVE-2012-2840 [HIGH] CVE-2012-2840: libexif - Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in t...
Off-by-one error in the exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted EXIF tags in an image.
Scope: local
bookworm: resolved (fixed in 0.6.20-3)
bullseye: resolved (fixed in 0.6.20-3)
forky: resolved (fixed in 0.6.20-3)
sid: resolved (fixed in 0.6.20-3)
trixie: resolved (fixed in 0.6.20-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2812 libexif various flaws [fedora-all]
bugzilla·2012-07-13·CVSS 6.4
CVE-2012-2813 [MEDIUM] CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2812 libexif various flaws [fedora-all]
CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2812 libexif various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
ht
Bugzilla
CVE-2012-2840 libexif: "exif_convert_utf16_to_utf8()" off-by-one
bugzilla·2012-07-11·CVSS 7.5
CVE-2012-2840 [HIGH] CVE-2012-2840 libexif: "exif_convert_utf16_to_utf8()" off-by-one
CVE-2012-2840 libexif: "exif_convert_utf16_to_utf8()" off-by-one
An off-by-one error in the exif_convert_utf16_to_utf8 function in libexif/exif-entry.c in libexif 0.6.20 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code via an image with crafted EXIF tags.
Discussion:
This now public via exif 0.6.21:
http://libexif.cvs.sourceforge.net/viewvc/libexif/libexif/ChangeLog?revision=1.370
http://libexif.cvs.sourceforge.net/viewvc/libexif/libexif/libexif/exif-utils.c?r1=1.16&r2=1.17&view=patch
---
Created libexif tracking bugs for this issue
Affects: fedora-all [bug 839917]
---
Upstream advisory:
http://sourceforge.net/mailarchive/message.php?msg_id=29534027
---
Acknowledgements:
Red Hat would like to thank Dan Fandrich for reporting th
Bugzilla
libexif security vulnerabilities
bugzilla·2012-07-05·CVSS 6.4
[MEDIUM] libexif security vulnerabilities
libexif security vulnerabilities
libexif ver. 0.6.20 and earlier suffers from a number of newly-discovered security vulnerabilities. The details will be made public with a new release of libexif that fixes them, which is planned to be the second week of July.
Very little has changed since version 0.6.20, so the new version should be a drop-in replacement. But, if you're interested in some advance testing, a prerelease version (that does NOT contain the security patches) is available at
http://sourceforge.net/projects/libexif/files/libexif/prerelease/libexif-0.6.21-pre1.tar.gz/download This prerelease should otherwise be substantially similar to the final release.
I'll update this bug with CVE numbers and more details before the release.
Discussion:
These are the CVEs fixed in version
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1255.htmlhttp://secunia.com/advisories/49988http://sourceforge.net/mailarchive/message.php?msg_id=29534027http://www.debian.org/security/2012/dsa-2559http://www.securityfocus.com/bid/54437http://www.ubuntu.com/usn/USN-1513-1http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1255.htmlhttp://secunia.com/advisories/49988http://sourceforge.net/mailarchive/message.php?msg_id=29534027http://www.debian.org/security/2012/dsa-2559http://www.securityfocus.com/bid/54437http://www.ubuntu.com/usn/USN-1513-1
2012-07-13
Published