cbcvebase.
CVE-2016-6328
published 2018-10-31

CVE-2016-6328: A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and…

PriorityP433high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
1.52%
71.9th percentile
A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metadata, even other applications' private data).

Affected

21 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlibexif< libexif 0.6.21-2.1 (bookworm)libexif 0.6.21-2.1 (bookworm)
googleandroid
libexif_projectlibexif< 0.6.220.6.22
libexif_projectlibexif>= 0 < 0.6.21-2.10.6.21-2.1
libexif_projectlibexif>= 0 < 0.6.21-2.10.6.21-2.1
libexif_projectlibexif>= 0 < 0.6.21-2.10.6.21-2.1
libexif_projectlibexif>= 0 < 0.6.21-2.10.6.21-2.1
libexif_projectlibexif>= 0 < 0.6.21-2ubuntu0.10.6.21-2ubuntu0.1
libexif_projectlibexif>= 0 < 0.6.21-4ubuntu0.10.6.21-4ubuntu0.1
libexif_projectlibexif>= 0 < 0.6.21-1ubuntu1+esm10.6.21-1ubuntu1+esm1
platformexternal_libexif>= 10:0 < 10:2021-01-0110:2021-01-01
platformexternal_libexif>= 11:0 < 11:2021-01-0111:2021-01-01
platformexternal_libexif>= 8.0:0 < 8.0:2021-01-018.0:2021-01-01
platformexternal_libexif>= 8.1:0 < 8.1:2021-01-018.1:2021-01-01
platformexternal_libexif>= 9:0 < 9:2021-01-019:2021-01-01

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv3.06.1MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.