Release date:
Updated on:
Affected Systems:
Libexif 0.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54437
Cve id: CVE-2012-2814
Libexif is a function library written in C. It is used to read and write EXIF metadata from graph files.
EXIF Tag Parsing Library (that is, libexif) 0.6.20 earlier versions of the exif-entry.c exif_entry_format_value function has a security vulnerability in processing specially crafted EXIF tags in graphics, allowing remote attackers to cause denial of service or execute arbitrary code.
<* Source: Mateusz Jurczyk
Yunho Kim
Dan Fandrich
Link: http://sourceforge.net/mailarchive/message.php? Ms. g_id = 29534027
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Libexif
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://libexif.sourceforge.net/