REDHAT-BUG-2457687: Integer Overflow
In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Do not run libexif on 32bit systems; process images that use libexif on 64bit systems instead, since the vulnerability only affects 32bit systems.
- Compensating control
Restrict local access to applications that invoke libexif and to processing of Nikon MakerNote metadata (limit execution to trusted users and contexts) to reduce the risk from local attackers.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2457687?
The severity of REDHAT-BUG-2457687 is medium with a score of 4.
How do I fix REDHAT-BUG-2457687?
To fix REDHAT-BUG-2457687, update the libexif software to the latest patched version.
Who is affected by REDHAT-BUG-2457687?
REDHAT-BUG-2457687 affects local users on 32-bit systems using libexif version 0.6.25 or earlier.
What type of vulnerability is represented by REDHAT-BUG-2457687?
REDHAT-BUG-2457687 represents an integer overflow vulnerability in Nikon MakerNote handling.
Can REDHAT-BUG-2457687 cause data leaks?
Yes, REDHAT-BUG-2457687 can be exploited to cause information leaks as well as crashes.