CVE-2012-2836: Buffer Overflow
The exifdataloaddata function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2836?
CVE-2012-2836 has a moderate severity rating due to its potential to cause denial of service and expose sensitive information.
How do I fix CVE-2012-2836?
To fix CVE-2012-2836, update the EXIF Tag Parsing Library (libexif) to version 0.6.21 or later.
What vulnerabilities does CVE-2012-2836 introduce?
CVE-2012-2836 introduces vulnerabilities that can lead to out-of-bounds read errors and possible exposure of sensitive memory information.
Which versions of libexif are affected by CVE-2012-2836?
CVE-2012-2836 affects libexif versions 0.6.20 and earlier.
Can CVE-2012-2836 be exploited remotely?
Yes, CVE-2012-2836 can be exploited remotely by sending crafted EXIF tags in an image.