Release date:
Updated on:
Affected Systems:
Libexif 0.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54437
Cve id: CVE-2012-2836
Libexif is a function library written in C. It is used to read and write EXIF metadata from graph files.
EXIF Tag Parsing Library (libexif) 0.6.21 earlier versions of the exif-entry.c exif_data_load_data function has a security vulnerability in processing specially crafted EXIF tags in graphics, allows remote attackers to cause DoS, attackers can exploit this vulnerability to read or leak sensitive information.
<* Source: Mateusz Jurczyk
Yunho Kim
Dan Fandrich
Link: http://sourceforge.net/mailarchive/message.php? Ms. g_id = 29534027
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Libexif
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://libexif.sourceforge.net/