libexif 'exif-entry.c' Tag Format Conversion Heap Buffer Overflow Vulnerability
BID:37022
Info
libexif 'exif-entry.c' Tag Format Conversion Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 37022 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-3895 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2009 12:00AM |
| Updated: | Feb 01 2012 10:10PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Sun Solaris 10_x86 Sun Solaris 10_sparc libexif libexif 0.6.18 Avaya IR 4.0 Avaya CMS Server 16.2 Avaya CMS Server 16.1 Avaya CMS Server 16.0 Avaya CMS Server 15.0 |
| Not Vulnerable: |
libexif libexif 0.6.19 |
Discussion
libexif 'exif-entry.c' Tag Format Conversion Heap Buffer Overflow Vulnerability
The 'libexif' library is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code within the context of an application using the affected library. Failed exploit attempts will result in a denial-of-service vulnerability.
The 'libexif' library is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code within the context of an application using the affected library. Failed exploit attempts will result in a denial-of-service vulnerability.
Exploit / POC
libexif 'exif-entry.c' Tag Format Conversion Heap Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
libexif 'exif-entry.c' Tag Format Conversion Heap Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
libexif 'exif-entry.c' Tag Format Conversion Heap Buffer Overflow Vulnerability
References:
References:
- [Libexif-devel] libexif project security advisory (Dan Fandrich)
- libexif Homepage (libexif)
- Multiple Vulnerabilities in Libexif (Oracle)
- ASA-2012-056: Multiple Vulnerabilities in Libexif (Oracle January 2012) (Avaya)