libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.
CVSS Details
- CVSS 3.0 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libexif | Oct 10, 2018 | Sep 21, 2017 |
| Debian | — | Upgrade libexif | May 19, 2020 | Sep 21, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade libexif | Nov 30, 2017 | Sep 21, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libexif | Nov 30, 2017 | Sep 21, 2017 |
| Oracle Solaris | — | Upgrade image/library/libexif to version 0.6.21-0.175.3.35.0.4.0 on Solaris 11.3 | Aug 24, 2018 | Sep 21, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 4, 2017 |
| Suse | — | Upgrade libexif12Upgrade libexifUpgrade libexif-devel-32bitUpgrade libexif12-32bitUpgrade libexif-x86Upgrade libexif-develUpgrade libexif-32bit | Jan 24, 2018 | Sep 21, 2017 |
| Ubuntu | — | Upgrade libexif12Upgrade libexif12 (Ubuntu Pro) | Feb 12, 2020 | Sep 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub