A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metadata, even other applications' private data).
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
- CVSS 3.0 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libexif | Aug 22, 2024 | Oct 31, 2018 |
| Debian | — | Upgrade libexif | May 19, 2020 | Oct 31, 2018 |
| Gentoo Linux | — | Upgrade media-libs/libexif. | Jul 28, 2020 | Oct 31, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libexif | Sep 12, 2019 | Oct 31, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libexif | Sep 25, 2019 | Oct 31, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libexif | Feb 3, 2021 | Oct 31, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 31, 2018 |
| Suse | — | Upgrade libexif12Upgrade libexif12-32bitUpgrade libexif-devel-32bitUpgrade libexif-devel | Jan 24, 2018 | Jan 24, 2018 |
| Ubuntu | — | Upgrade libexif12 (Ubuntu Pro)Upgrade libexif12 | Feb 12, 2020 | Jan 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub