// For flags

CVE-2006-4168

libexif integer overflow

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow.

Desbordamiento de entero en la función exif_data_load_data_entry en libexif/exif-data.c en Libexif anterior a 0.6.16 permite a atacantes remotos provocar denegación de servicio (caida de aplicación) o ejecutar código de su elección a través de una imagen con diferentes componentes EXIF, lo cual dispara un desbordamiento de búfer basado en pila.

Remote exploitation of a integer overflow vulnerability in libexif, as included in various vendors' operating system distributions, could allow attackers to crash the process or execute arbitrary code. The problem exists while parsing a tagged image with a large number of Exif components. Applications using this library are susceptible to a heap overflow when an integer overflow is triggered in the exif_data_load_data_entry function. iDefense confirmed the existence of this vulnerability in versions 0.6.13 through 0.6.15 of libexif.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-08-16 CVE Reserved
  • 2007-06-14 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-07-26 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-190: Integer Overflow or Wraparound
CAPEC
References (29)
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Libexif
Search vendor "Libexif"
Libexif
Search vendor "Libexif" for product "Libexif"
0.6.9
Search vendor "Libexif" for product "Libexif" and version "0.6.9"
-
Affected
Libexif
Search vendor "Libexif"
Libexif
Search vendor "Libexif" for product "Libexif"
0.6.11
Search vendor "Libexif" for product "Libexif" and version "0.6.11"
-
Affected
Libexif
Search vendor "Libexif"
Libexif
Search vendor "Libexif" for product "Libexif"
0.6.12
Search vendor "Libexif" for product "Libexif" and version "0.6.12"
-
Affected
Libexif
Search vendor "Libexif"
Libexif
Search vendor "Libexif" for product "Libexif"
0.6.13
Search vendor "Libexif" for product "Libexif" and version "0.6.13"
-
Affected
Libexif
Search vendor "Libexif"
Libexif
Search vendor "Libexif" for product "Libexif"
0.6.14
Search vendor "Libexif" for product "Libexif" and version "0.6.14"
-
Affected
Libexif
Search vendor "Libexif"
Libexif
Search vendor "Libexif" for product "Libexif"
0.6.15
Search vendor "Libexif" for product "Libexif" and version "0.6.15"
-
Affected