CVE-2012-2845
published 2012-07-13CVE-2012-2845: Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer…
PriorityP426medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
3.56%
88.2th percentile
Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curtis_galloway | exif | — | — |
| debian | exif | < exif 0.6.20-2 (bookworm) | exif 0.6.20-2 (bookworm) |
| exif | exif | >= 0 < 0.6.20-2 | 0.6.20-2 |
| exif | exif | >= 0 < 0.6.20-2 | 0.6.20-2 |
| exif | exif | >= 0 < 0.6.20-2 | 0.6.20-2 |
| exif | exif | >= 0 < 0.6.20-2 | 0.6.20-2 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.4MEDIUM
vendor_debian6.4LOW
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
exif: Integer overflow, leading to DoS (buffer over-read and application crash) in jpeg_data_load_data routine
vendor_redhat·2012-07-12·CVSS 6.4
CVE-2012-2845 [MEDIUM] CWE-190 exif: Integer overflow, leading to DoS (buffer over-read and application crash) in jpeg_data_load_data routine
exif: Integer overflow, leading to DoS (buffer over-read and application crash) in jpeg_data_load_data routine
Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.
Package: libjpeg (Red Hat Enterprise Linux 5) - Not affected
Package: libjpeg (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-2845: exif - Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg i...
vendor_debian·2012·CVSS 6.4
CVE-2012-2845 [MEDIUM] CVE-2012-2845: exif - Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg i...
Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.
Scope: local
bookworm: resolved (fixed in 0.6.20-2)
bullseye: resolved (fixed in 0.6.20-2)
forky: resolved (fixed in 0.6.20-2)
sid: resolved (fixed in 0.6.20-2)
trixie: resolved (fixed in 0.6.20-2)
GHSA
GHSA-f92q-2q89-r8mx: Integer overflow in the jpeg_data_load_data function in jpeg-data
ghsa_unreviewed·2022-05-17
CVE-2012-2845 [MEDIUM] GHSA-f92q-2q89-r8mx: Integer overflow in the jpeg_data_load_data function in jpeg-data
Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.
OSV
CVE-2012-2845: Integer overflow in the jpeg_data_load_data function in jpeg-data
osv·2012-07-13·CVSS 6.4
CVE-2012-2845 [MEDIUM] CVE-2012-2845: Integer overflow in the jpeg_data_load_data function in jpeg-data
Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2845 exif: Integer overflow, leading to DoS (buffer over-read and application crash) in jpeg_data_load_data routine
bugzilla·2012-07-13·CVSS 6.4
CVE-2012-2845 [MEDIUM] CVE-2012-2845 exif: Integer overflow, leading to DoS (buffer over-read and application crash) in jpeg_data_load_data routine
CVE-2012-2845 exif: Integer overflow, leading to DoS (buffer over-read and application crash) in jpeg_data_load_data routine
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-2845 to the following vulnerability:
Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.
References:
[1] http://sourceforge.net/mailarchive/message.php?msg_id=29534027
Upstream patch:
[2] http://libexif.cvs.sourceforge.net/viewvc/libexif/exif/libjpeg/jpeg-data.c?r1=1.23&r2=1.24&view=patch
Revision log:
[3] http://libexif.cvs.sourceforge.net/viewvc/libexif/exif/libjpeg/jpeg-data.c?view=log
Di
Bugzilla
CVE-2012-2845 exif: Integer overflow, leading to DoS (buffer over-read and application crash) in jpeg_data_load_data routine [fedora-all]
bugzilla·2012-07-13·CVSS 6.4
CVE-2012-2845 [MEDIUM] CVE-2012-2845 exif: Integer overflow, leading to DoS (buffer over-read and application crash) in jpeg_data_load_data routine [fedora-all]
CVE-2012-2845 exif: Integer overflow, leading to DoS (buffer over-read and application crash) in jpeg_data_load_data routine [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission lin
Bugzilla
libexif security vulnerabilities
bugzilla·2012-07-05·CVSS 6.4
[MEDIUM] libexif security vulnerabilities
libexif security vulnerabilities
libexif ver. 0.6.20 and earlier suffers from a number of newly-discovered security vulnerabilities. The details will be made public with a new release of libexif that fixes them, which is planned to be the second week of July.
Very little has changed since version 0.6.20, so the new version should be a drop-in replacement. But, if you're interested in some advance testing, a prerelease version (that does NOT contain the security patches) is available at
http://sourceforge.net/projects/libexif/files/libexif/prerelease/libexif-0.6.21-pre1.tar.gz/download This prerelease should otherwise be substantially similar to the final release.
I'll update this bug with CVE numbers and more details before the release.
Discussion:
These are the CVEs fixed in version
http://secunia.com/advisories/49988http://sourceforge.net/mailarchive/message.php?msg_id=29534027http://www.mandriva.com/security/advisories?name=MDVSA-2012:107http://www.securityfocus.com/bid/54437http://secunia.com/advisories/49988http://sourceforge.net/mailarchive/message.php?msg_id=29534027http://www.mandriva.com/security/advisories?name=MDVSA-2012:107http://www.securityfocus.com/bid/54437
2012-07-13
Published