Release date:
Updated on:
Affected Systems:
Libexif 0.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54437
Cve id: CVE-2012-2813
Libexif is a function library written in C. It is used to read and write EXIF metadata from graph files.
EXIF Tag Parsing Library (libexif) 0.6.21 earlier versions of the exif-entry.c exif_convert_utf16_to_utf8 function has a security vulnerability in processing specially crafted EXIF tags in graphics, can allow remote attackers cause denial of service, attackers can exploit this vulnerability to read or leak sensitive information.
<* Source: Mateusz Jurczyk
Yunho Kim
Dan Fandrich
Link: http://sourceforge.net/mailarchive/message.php? Ms. g_id = 29534027
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Libexif
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://libexif.sourceforge.net/