First published: Mon Dec 17 2007(Updated: )
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/0.15 | <5. | 5. |
CentOS Dos2unix | ||
Exiv2 | <0.16 | |
Debian | =3.1 | |
Debian | =4.0 | |
Ubuntu | =7.04 | |
Ubuntu | =7.10 | |
Ubuntu | =8.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6353 has a moderate severity rating due to its potential to allow arbitrary code execution.
To fix CVE-2007-6353, update the Exiv2 library to version 0.16 or higher.
CVE-2007-6353 affects various systems including Exiv2 versions lower than 0.16 and specific Debian and Ubuntu versions.
CVE-2007-6353 is caused by an integer overflow in the EXIF parsing code of the Exiv2 library.
Yes, CVE-2007-6353 can be exploited to create a denial of service due to a heap-based buffer overflow.