CVE-2012-2841
published 2012-07-13CVE-2012-2841: Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.70%
92.1th percentile
Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libexif | < libexif 0.6.20-3 (bookworm) | libexif 0.6.20-3 (bookworm) |
| libexif_project | libexif | — | — |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
| libexif_project | libexif | >= 0 < 0.6.20-3 | 0.6.20-3 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gf6f-3mxg-9758: Integer underflow in the exif_entry_get_value function in exif-entry
ghsa_unreviewed·2022-05-13
CVE-2012-2841 [HIGH] GHSA-gf6f-3mxg-9758: Integer underflow in the exif_entry_get_value function in exif-entry
Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.
OSV
CVE-2012-2841: Integer underflow in the exif_entry_get_value function in exif-entry
osv·2012-07-13·CVSS 7.5
CVE-2012-2841 [HIGH] CVE-2012-2841: Integer underflow in the exif_entry_get_value function in exif-entry
Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.
Ubuntu
libexif vulnerabilities
vendor_ubuntu·2012-07-23·CVSS 6.4
CVE-2012-2812 [MEDIUM] libexif vulnerabilities
Title: libexif vulnerabilities
Summary: libexif could be made to crash, run programs as your login, or expose
sensitive information if it opened a specially crafted file.
Mateusz Jurczyk discovered that libexif incorrectly parsed certain
malformed EXIF tags. If a user or automated system were tricked into
processing a specially crafted image file, an attacker could cause libexif
to crash, leading to a denial of service, or possibly obtain sensitive
information. (CVE-2012-2812, CVE-2012-2813)
Mateusz Jurczyk discovered that libexif incorrectly parsed certain
malformed EXIF tags. If a user or automated system were tricked into
processing a specially crafted image file, an attacker could cause libexif
to crash, leading to a denial of service, or possibly execute arbitrary
code. (CVE-2012-2
Red Hat
libexif: "exif_entry_get_value()" integer underflow
vendor_redhat·2012-07-12·CVSS 7.5
CVE-2012-2841 [HIGH] CWE-190 libexif: "exif_entry_get_value()" integer underflow
libexif: "exif_entry_get_value()" integer underflow
Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.
Debian
CVE-2012-2841: libexif - Integer underflow in the exif_entry_get_value function in exif-entry.c in the EX...
vendor_debian·2012·CVSS 7.5
CVE-2012-2841 [HIGH] CVE-2012-2841: libexif - Integer underflow in the exif_entry_get_value function in exif-entry.c in the EX...
Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.6.20-3)
bullseye: resolved (fixed in 0.6.20-3)
forky: resolved (fixed in 0.6.20-3)
sid: resolved (fixed in 0.6.20-3)
trixie: resolved (fixed in 0.6.20-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2812 libexif various flaws [fedora-all]
bugzilla·2012-07-13·CVSS 6.4
CVE-2012-2813 [MEDIUM] CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2812 libexif various flaws [fedora-all]
CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2812 libexif various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
ht
Bugzilla
CVE-2012-2841 libexif: "exif_entry_get_value()" integer underflow
bugzilla·2012-07-11·CVSS 7.5
CVE-2012-2841 [HIGH] CVE-2012-2841 libexif: "exif_entry_get_value()" integer underflow
CVE-2012-2841 libexif: "exif_entry_get_value()" integer underflow
An integer underflow in the exif_entry_get_value function can cause a heap overflow and potentially arbitrary code execution while formatting an EXIF tag, if the function is called with a buffer size parameter equal to zero or one.
Discussion:
This now public via exif 0.6.21:
http://libexif.cvs.sourceforge.net/viewvc/libexif/libexif/ChangeLog?revision=1.370
http://libexif.cvs.sourceforge.net/viewvc/libexif/libexif/libexif/exif-entry.c?r1=1.148&r2=1.149&view=patch
---
Created libexif tracking bugs for this issue
Affects: fedora-all [bug 839917]
---
Upstream advisory:
http://sourceforge.net/mailarchive/message.php?msg_id=29534027
---
Acknowledgements:
Red Hat would like to thank Dan Fandrich for reporting this issu
Bugzilla
libexif security vulnerabilities
bugzilla·2012-07-05·CVSS 6.4
[MEDIUM] libexif security vulnerabilities
libexif security vulnerabilities
libexif ver. 0.6.20 and earlier suffers from a number of newly-discovered security vulnerabilities. The details will be made public with a new release of libexif that fixes them, which is planned to be the second week of July.
Very little has changed since version 0.6.20, so the new version should be a drop-in replacement. But, if you're interested in some advance testing, a prerelease version (that does NOT contain the security patches) is available at
http://sourceforge.net/projects/libexif/files/libexif/prerelease/libexif-0.6.21-pre1.tar.gz/download This prerelease should otherwise be substantially similar to the final release.
I'll update this bug with CVE numbers and more details before the release.
Discussion:
These are the CVEs fixed in version
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1255.htmlhttp://secunia.com/advisories/49988http://sourceforge.net/mailarchive/message.php?msg_id=29534027http://www.debian.org/security/2012/dsa-2559http://www.securityfocus.com/bid/54437http://www.ubuntu.com/usn/USN-1513-1http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1255.htmlhttp://secunia.com/advisories/49988http://sourceforge.net/mailarchive/message.php?msg_id=29534027http://www.debian.org/security/2012/dsa-2559http://www.securityfocus.com/bid/54437http://www.ubuntu.com/usn/USN-1513-1
2012-07-13
Published