libexif Multiple Remote Vulnerabilities
BID:54437
Info
libexif Multiple Remote Vulnerabilities
| Bugtraq ID: | 54437 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-2812 CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841 CVE-2012-2845 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2012 12:00AM |
| Updated: | Jul 05 2016 09:27PM |
| Credit: | Mateusz Jurczyk, Yunho Kim, Dan Fandrich |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server for VMware 11 SP1 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise Desktop 11 SP2 SuSE SUSE Linux Enterprise Desktop 11 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP4 Slackware Linux x86_64 -current Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 libexif libexif 0.6.19 libexif libexif 0.6.18 libexif libexif 0.6.16 libexif libexif 0.6.15 libexif libexif 0.6.14 libexif libexif 0.6.13 libexif libexif 0.6.12 libexif libexif 0.6.11 libexif libexif 0.6.9 libexif libexif 0.5.12 libexif libexif 0.5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 |
| Not Vulnerable: | |
Discussion
libexif Multiple Remote Vulnerabilities
The libexif library is prone to multiple remote vulnerabilities.
An attacker could exploit these issues to execute arbitrary code in the context of the affected application or cause denial-of-service conditions.
libexif versions prior to 0.6.21 are vulnerable.
The libexif library is prone to multiple remote vulnerabilities.
An attacker could exploit these issues to execute arbitrary code in the context of the affected application or cause denial-of-service conditions.
libexif versions prior to 0.6.21 are vulnerable.
Exploit / POC
libexif Multiple Remote Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
libexif Multiple Remote Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.0
Slackware Linux -current
Slackware Linux 12.2
Slackware Linux 13.1 x86_64
Slackware Linux 13.1
Slackware Linux 12.1
Slackware Linux x86_64 -current
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Slackware Linux 13.0 x86_64
Slackware Linux 13.37 x86_64
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.0
-
Slackware libexif-0.6.21-i486-1_slack12.0.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ libexif-0.6.21-i486-1_slack12.0.tgz
Slackware Linux -current
-
Slackware libexif-0.6.21-i486-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/li bexif-0.6.21-i486-1.txz
Slackware Linux 12.2
-
Slackware libexif-0.6.21-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ libexif-0.6.21-i486-1_slack12.2.tgz
Slackware Linux 13.1 x86_64
-
Slackware libexif-0.6.21-x86_64-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/package s/libexif-0.6.21-x86_64-1_slack13.1.txz
Slackware Linux 13.1
-
Slackware libexif-0.6.21-i486-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ libexif-0.6.21-i486-1_slack13.1.txz
Slackware Linux 12.1
-
Slackware libexif-0.6.21-i486-1_slack12.1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/ libexif-0.6.21-i486-1_slack12.1.tgz
Slackware Linux x86_64 -current
-
Slackware libexif-0.6.21-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ l/libexif-0.6.21-x86_64-1.txz
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva exif-0.6.21-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva exif-0.6.21-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Slackware Linux 13.0 x86_64
-
Slackware libexif-0.6.21-x86_64-1_slack13.0.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/package s/libexif-0.6.21-x86_64-1_slack13.0.txz
Slackware Linux 13.37 x86_64
-
Slackware libexif-0.6.21-x86_64-1_slack13.37.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packag es/libexif-0.6.21-x86_64-1_slack13.37.txz
References
libexif Multiple Remote Vulnerabilities
References:
References:
- Bug 771229 - VUL-0: libexif: fixed various overflows (Bugzilla )
- libexif Homepage (libexif)
- ASA-2012-447 : libexif security update (RHSA-2012-1255) (Avaya)
- BSRT-2013-009 Vulnerabilities in libexif impact BlackBerry PlayBook tablet softw (Blackberry)
- Oracle Solaris Third Party Bulletin - January 2016 (Oracle)
- Xerox Security Bulletin XRX13-007 (Xerox)