EXIF Library EXIF File Processing Integer Overflow Vulnerability
BID:24461
Info
EXIF Library EXIF File Processing Integer Overflow Vulnerability
| Bugtraq ID: | 24461 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4168 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2007 12:00AM |
| Updated: | Mar 19 2015 09:44AM |
| Credit: | This vulnerability was discovered by Sean Larsson of iDefense Labs. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 Sun Solaris 10_x86 Sun Solaris 10_sparc Slackware Linux 10.2 Slackware Linux 11.0 Slackware Linux -current S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Desktop 4.0 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 libexif libexif 0.6.15 libexif libexif 0.6.14 libexif libexif 0.6.13 Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Messaging Storage Server MM3.0 Avaya IR 4.0 Avaya CMS Server 16.2 Avaya CMS Server 16.1 Avaya CMS Server 16.0 Avaya CMS Server 15.0 |
| Not Vulnerable: |
libexif libexif 0.6.16 |
Discussion
EXIF Library EXIF File Processing Integer Overflow Vulnerability
The 'libexif' library is reported prone to an integer-overflow vulnerability. Reportedly, the issue presents itself when the affected library is processing malformed EXIF files.
Attackers may leverage this issue to execute arbitrary code in the context of an application that is linked to the vulnerable library. Failed exploit attempts will likely result in denial-of-service conditions.
This issue affects 'libexif' 0.6.13 to 0.6.15; other versions may also be affected.
The 'libexif' library is reported prone to an integer-overflow vulnerability. Reportedly, the issue presents itself when the affected library is processing malformed EXIF files.
Attackers may leverage this issue to execute arbitrary code in the context of an application that is linked to the vulnerable library. Failed exploit attempts will likely result in denial-of-service conditions.
This issue affects 'libexif' 0.6.13 to 0.6.15; other versions may also be affected.
Exploit / POC
EXIF Library EXIF File Processing Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
EXIF Library EXIF File Processing Integer Overflow Vulnerability
Solution:
The vendor has released version 0.6.16 to address this issue; please see the reference section for details.
Slackware Linux -current
Slackware Linux 11.0
libexif libexif 0.6.13
libexif libexif 0.6.14
libexif libexif 0.6.15
Slackware Linux 10.2
Solution:
The vendor has released version 0.6.16 to address this issue; please see the reference section for details.
Slackware Linux -current
-
Slackware libexif-0.6.16-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/li bexif-0.6.16-i486-1.tgz
Slackware Linux 11.0
-
Slackware libexif-0.6.16-i486-1_slack11.0.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/ libexif-0.6.16-i486-1_slack11.0.tgz
libexif libexif 0.6.13
-
libexif libexif-0.6.16.tar.gz
http://internap.dl.sourceforge.net/sourceforge/libexif/libexif-0.6.16. tar.gz
libexif libexif 0.6.14
-
libexif libexif-0.6.16.tar.gz
http://internap.dl.sourceforge.net/sourceforge/libexif/libexif-0.6.16. tar.gz
libexif libexif 0.6.15
-
libexif libexif-0.6.16.tar.gz
http://internap.dl.sourceforge.net/sourceforge/libexif/libexif-0.6.16. tar.gz
Slackware Linux 10.2
-
Slackware libexif-0.6.16-i486-1_slack10.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/ libexif-0.6.16-i486-1_slack10.2.tgz
References
EXIF Library EXIF File Processing Integer Overflow Vulnerability
References:
References:
- File Release Notes and Changelog libexif 0.6.16 (libexif)
- libexif Homepage (libexif)
- Multiple Vulnerabilities in Libexif (Oracle)
- FLEA-2007-0028-1: libexif ( Foresight Linux Essential Announcement Service
- iDefense Security Advisory 06.13.07: Multiple Vendor libexif Integer Overflow He (iDefense Labs
) - ASA-2007-286 libexif integer overflow (RHSA-2007-0501) (Avaya)
- ASA-2012-056: Multiple Vulnerabilities in Libexif (Oracle January 2012) (Avaya)
- RHSA-2007:0501-4 libexif integer overflow (Red Hat)