libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.
CVSS Details
- CVSS 3.0 Base Score: 9.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-libexif | Oct 10, 2018 | Sep 21, 2017 | |
| Debian | debian-upgrade-libexif | May 19, 2020 | Sep 21, 2017 | |
| Huawei Euleros 2_0_sp1 | huawei-euleros-2_0_sp1-upgrade-libexif | Nov 30, 2017 | Sep 21, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-libexif | Nov 30, 2017 | Sep 21, 2017 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-image-library-libexif-0-6-21-0-175-3-35-0-4-0 | Aug 24, 2018 | Sep 21, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Jul 4, 2017 | |
| Suse | — | suse-upgrade-libexifsuse-upgrade-libexif-32bitsuse-upgrade-libexif-develsuse-upgrade-libexif-devel-32bitsuse-upgrade-libexif-x86suse-upgrade-libexif12suse-upgrade-libexif12-32bit | Jan 24, 2018 | Sep 21, 2017 |
| Ubuntu | ubuntu-pro-upgrade-libexif12ubuntu-upgrade-libexif12 | Feb 12, 2020 | Sep 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub