Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exiv2 | Jul 30, 2024 | Dec 20, 2007 |
| Gentoo Linux | — | Upgrade media-gfx/exiv2. | Oct 30, 2017 | Dec 19, 2007 |
| Suse | — | Upgrade libexiv2-28-x86-64-v3Upgrade libexiv2-4Upgrade libexiv2-28Upgrade libexiv2-4-x86Upgrade libexiv2-4-32bitUpgrade libexiv2-devel | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libexiv2-0Upgrade libexiv2-2Upgrade libexiv2-0.12 | Nov 8, 2024 | Dec 20, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub