LibEXIF 0.6.x - Exif_Data_Load_Data_Entry Remote Integer Overflow
Author: Victor Stinner
type: dos
platform: linux
port:
date_added: 2007-05-11
date_updated: 2013-12-07
verified: 1
codes: CVE-2007-2645;OSVDB-35978
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/23927/info
The libexif library is prone to an integer-overflow vulnerability because the software fails to properly ensure that integer math operations do not result in overflows.
Successful exploits of this vulnerability allow remote attackers to execute arbitrary machine code in the context of an application using the vulnerable library. Failed attempts will likely result in denial-of-service conditions.
Versions of libexif prior to 0.6.14 are vulnerable to this issue.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/30024.jpg