First published: Fri Dec 14 2007(Updated: )
An infinite recursion flaw was found in libexif. This could be leveraged by an attacker to crash an application using libexif to process image data content.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Libexif12 | =0.6.14 | |
SUSE Libexif12 | =0.6.15 | |
SUSE Libexif12 | <=0.6.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6351 is classified as a denial of service vulnerability due to its potential to cause infinite recursion in applications using libexif.
To fix CVE-2007-6351, you should upgrade libexif to version 0.6.17 or later.
CVE-2007-6351 affects libexif versions 0.6.16 and earlier.
CVE-2007-6351 can be exploited by context-dependent attackers to crash applications that process specially crafted image files.
There are no documented workarounds for CVE-2007-6351 other than upgrading to a patched version of libexif.