Bug 425561 (CVE-2007-6352) - CVE-2007-6352 libexif integer overflow
Summary: CVE-2007-6352 libexif integer overflow
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2007-6352
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 425621 425631 425641 425651 425661 425671 425681 833926
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-12-14 22:15 UTC by Josh Bressers
Modified: 2019-09-29 12:22 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-01-11 17:13:09 UTC
Embargoed:


Attachments (Terms of Use)
Upstream patch (570 bytes, patch)
2007-12-14 22:15 UTC, Josh Bressers
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2007:1165 0 normal SHIPPED_LIVE Moderate: libexif security update 2007-12-19 15:34:59 UTC
Red Hat Product Errata RHSA-2007:1166 0 normal SHIPPED_LIVE Moderate: libexif security update 2007-12-19 15:45:20 UTC

Description Josh Bressers 2007-12-14 22:15:56 UTC
An integer overflow flaw was found in libexif.  This flaw could be leveraged by
an attacker to execute arbitrary code withe the permissions of the application
parsing the EXIF image data.

Comment 1 Josh Bressers 2007-12-14 22:15:56 UTC
Created attachment 289541 [details]
Upstream patch

Comment 7 Tomas Hoger 2007-12-19 16:54:30 UTC
Fixed in affected Red Hat Enterprise Linux versions:
  http://rhn.redhat.com/errata/RHSA-2007-1165.html
  http://rhn.redhat.com/errata/RHSA-2007-1166.html


Note You need to log in before you can comment on or make changes to this bug.