Red Hat Bugzilla – Bug 839188
CVE-2012-2840 libexif: "exif_convert_utf16_to_utf8()" off-by-one
Last modified: 2016-03-04 06:22:00 EST
An off-by-one error in the exif_convert_utf16_to_utf8 function in libexif/exif-entry.c in libexif 0.6.20 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code via an image with crafted EXIF tags.
This now public via exif 0.6.21:
Created libexif tracking bugs for this issue
Affects: fedora-all [bug 839917]
Red Hat would like to thank Dan Fandrich for reporting this issue.
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2012:1255 https://rhn.redhat.com/errata/RHSA-2012-1255.html
libexif-0.6.21-2.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.
libexif-0.6.21-2.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.