CVE-2012-2840: High severity Libexif Project Libexif vulnerability
Published Jul 13, 2012
·Updated
Off-by-one error in the exifconvertutf16toutf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted EXIF tags in an image.
Affected Software
6 affected components
Libexif Project Libexif<=0.6.20
Libexif Project Libexif=0.6.14
Libexif Project Libexif=0.6.15
Libexif Project Libexif=0.6.16
Libexif Project Libexif=0.6.18
Libexif Project Libexif=0.6.19
Event History
Jul 13, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2840?
CVE-2012-2840 has a medium severity level, potentially leading to denial of service or arbitrary code execution.
2
How do I fix CVE-2012-2840?
To fix CVE-2012-2840, upgrade libexif to version 0.6.21 or later.
3
What software is affected by CVE-2012-2840?
CVE-2012-2840 affects libexif versions prior to 0.6.21, including versions 0.6.14 to 0.6.20.
4
Can CVE-2012-2840 be exploited remotely?
Yes, CVE-2012-2840 can be exploited remotely through crafted EXIF tags in an image.
5
What impact does CVE-2012-2840 have on applications?
CVE-2012-2840 can cause denial of service and may allow an attacker to execute arbitrary code in affected applications.