CVE-2007-6352: Integer Overflow
An integer overflow flaw was found in libexif. This flaw could be leveraged by an attacker to execute arbitrary code withe the permissions of the application parsing the EXIF image data.
Other sources
Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exifdataloaddatathumbnail function in exif-data.c.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6352?
CVE-2007-6352 is classified as a high severity vulnerability due to its potential to allow attackers to execute arbitrary code.
How do I fix CVE-2007-6352?
To fix CVE-2007-6352, upgrade libexif to version 0.6.17 or later.
What applications are affected by CVE-2007-6352?
CVE-2007-6352 affects libexif version 0.6.16 and earlier.
What type of flaw is described in CVE-2007-6352?
CVE-2007-6352 describes an integer overflow flaw that can be exploited to execute arbitrary code.
Can CVE-2007-6352 be exploited remotely?
Yes, CVE-2007-6352 can be exploited by attackers through specially crafted EXIF image data.