CVE-2012-2841
libexif: "exif_entry_get_value()" integer underflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.
Un desbordamiento de enteros en la función exif_entry_get_value en Exif-entry.c en la biblioteca EXIF Tag Parsing Library (también conocida como libexif) v0.6.20 podría permitir a atacantes remotos ejecutar código de su elección a través de vectores relacionados con parámetro "buffer-size" modificado a mano durante el formateo de una etiqueta EXIF, dando lugar a un desbordamiento de búfer basado en memoria dinámica (heap).
Multiple vulnerabilities have been found in libexif and exif, some of which may allow execution of arbitrary code. Versions less than 0.6.21 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-05-19 CVE Reserved
- 2012-07-13 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/49988 | Third Party Advisory | |
http://sourceforge.net/mailarchive/message.php?msg_id=29534027 | Mailing List | |
http://www.securityfocus.com/bid/54437 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00014.html | 2023-11-07 | |
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2012-1255.html | 2023-11-07 | |
http://www.debian.org/security/2012/dsa-2559 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1513-1 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2012-2841 | 2012-09-11 | |
https://bugzilla.redhat.com/show_bug.cgi?id=839189 | 2012-09-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Libexif Project Search vendor "Libexif Project" | Libexif Search vendor "Libexif Project" for product "Libexif" | 0.6.20 Search vendor "Libexif Project" for product "Libexif" and version "0.6.20" | - |
Affected
|