First published: Fri Jul 13 2012(Updated: )
The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Libexif12 | <=0.6.20 | |
SUSE Libexif12 | =0.6.14 | |
SUSE Libexif12 | =0.6.15 | |
SUSE Libexif12 | =0.6.16 | |
SUSE Libexif12 | =0.6.18 | |
SUSE Libexif12 | =0.6.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2837 has a moderate severity level due to the potential for denial of service attacks.
To fix CVE-2012-2837, update your libexif installation to version 0.6.21 or later.
CVE-2012-2837 affects libexif versions prior to 0.6.21, including 0.6.14 to 0.6.20.
CVE-2012-2837 is a denial of service vulnerability caused by a divide-by-zero error in handling crafted EXIF tags.
Yes, CVE-2012-2837 can affect any user of the vulnerable versions of the libexif library when processing maliciously crafted images.