CVE-2012-2837: Medium severity Libexif Project Libexif vulnerability
The mnoteolympusentrygetvalue function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2837?
CVE-2012-2837 has a moderate severity level due to the potential for denial of service attacks.
How do I fix CVE-2012-2837?
To fix CVE-2012-2837, update your libexif installation to version 0.6.21 or later.
What versions of libexif are affected by CVE-2012-2837?
CVE-2012-2837 affects libexif versions prior to 0.6.21, including 0.6.14 to 0.6.20.
What type of vulnerability is CVE-2012-2837?
CVE-2012-2837 is a denial of service vulnerability caused by a divide-by-zero error in handling crafted EXIF tags.
Can CVE-2012-2837 affect all users of libexif?
Yes, CVE-2012-2837 can affect any user of the vulnerable versions of the libexif library when processing maliciously crafted images.