Bug 425561 (CVE-2007-6352) - CVE-2007-6352 libexif integer overflow
Summary: CVE-2007-6352 libexif integer overflow
Status: CLOSED ERRATA
Alias: CVE-2007-6352
Product: Security Response
Classification: Other
Component: vulnerability   
(Show other bugs)
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,reported=20071214,sou...
Keywords: Security
Depends On: 425621 425631 425641 425651 425661 425671 425681 833926
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-12-14 22:15 UTC by Josh Bressers
Modified: 2016-03-04 11:12 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2008-01-11 17:13:09 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Upstream patch (570 bytes, patch)
2007-12-14 22:15 UTC, Josh Bressers
no flags Details | Diff


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2007:1165 normal SHIPPED_LIVE Moderate: libexif security update 2007-12-19 15:34:59 UTC
Red Hat Product Errata RHSA-2007:1166 normal SHIPPED_LIVE Moderate: libexif security update 2007-12-19 15:45:20 UTC

Description Josh Bressers 2007-12-14 22:15:56 UTC
An integer overflow flaw was found in libexif.  This flaw could be leveraged by
an attacker to execute arbitrary code withe the permissions of the application
parsing the EXIF image data.

Comment 1 Josh Bressers 2007-12-14 22:15:56 UTC
Created attachment 289541 [details]
Upstream patch

Comment 7 Tomas Hoger 2007-12-19 16:54:30 UTC
Fixed in affected Red Hat Enterprise Linux versions:
  http://rhn.redhat.com/errata/RHSA-2007-1165.html
  http://rhn.redhat.com/errata/RHSA-2007-1166.html


Note You need to log in before you can comment on or make changes to this bug.