[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.8] libexif: Out-of-bounds heap read in exif_data_save_data_entry function (CVE-2017-7544)

ID: oval:org.secpod.oval:def:1801202Date: (C)2018-10-12   (M)2022-10-19
Class: PATCHFamily: unix




One heap-based out-of-bounds read vulnerabiltiy exists in libexif-0.6.21. When saving the data of an entry tagged with EXIF_TAG_MAKER_NOTE to a buffer and copying the data of the exif entry, there is a mismatch between the computed read size of the entry data and the size of the allocated entry data. The vulnerability can cause Denial-of-Service, even Information Disclosure .

Platform:
Alpine Linux 3.8
Product:
libexif
Reference:
9522
CVE-2017-7544
CVE    1
CVE-2017-7544
CPE    2
cpe:/o:alpinelinux:alpine_linux:3.8
cpe:/a:curtis_galloway:libexif

© SecPod Technologies