[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256148

 
 

909

 
 

199106

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-2645Date: (C)2007-05-14   (M)2023-12-22


Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted EXIF data, involving the (1) doff or (2) s variable.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://www.securityfocus.com/archive/1/470502/100/100/threaded
BID-23927
SECUNIA-25235
SECUNIA-25540
SECUNIA-25569
SECUNIA-25599
SECUNIA-25621
SECUNIA-25932
SECUNIA-26083
SECUNIA-28776
OSVDB-35978
ADV-2007-1761
DSA-1487
GLSA-200706-01
MDKSA-2007:118
SUSE-SA:2007:039
SUSE-SR:2007:014
USN-471-1
http://sourceforge.net/project/shownotes.php?release_id=507447
http://sourceforge.net/tracker/index.php?func=detail&aid=1716196&group_id=12272&atid=112272
https://issues.rpath.com/browse/RPL-1431
libexif-exifdataloaddata-integer-overflow(34233)

OVAL    1
oval:org.mitre.oval:def:8088

© SecPod Technologies