MEDIUM
Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via an invalid EXIF image
Published Nov 20, 2009
6.8
MEDIUMCVSS 2.0
EPSS 5.12%
Description
Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via an invalid EXIF image. NOTE: some of these details are obtained from third party information.
Affected products
No data.
- 0.6.18
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of libexif as shipped with Red Hat Enterprise Linux 4, or 5.
Weaknesses (1)
References (13)
- http://bugs.debian.org/557137 x_refsource_CONFIRM
- http://bugs.gentoo.org/show_bug.cgi?id=293190 x_refsource_CONFIRM
- http://libexif.cvs.sourceforge.net/viewvc/libexif/libexif/NEWS?view=markup&pathrev=libexif-0_6_19-release x_refsource_CONFIRMPatch
- http://secunia.com/advisories/37378 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://sourceforge.net/mailarchive/message.php?msg_name=20091113072359.GA22681%40coneharvesters.com mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2009/11/19/2 mailing-listx_refsource_MLIST
- http://www.osvdb.org/59956 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/37022 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2009/3243 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-3895 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54275 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-3895
- https://www.cve.org/CVERecord?id=CVE-2009-3895
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 20, 2009
Updated Aug 7, 2024
Reserved Nov 5, 2009
Link CVE-2009-3895
CISA Vulnrichment
Updated n/a