Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2012-2836
HistoryJul 13, 2012 - 10:34 a.m.

CVE-2012-2836

2012-07-1310:34:59
Alpine Linux Development Team
security.alpinelinux.org
20

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

AI Score

6.7

Confidence

Low

EPSS

0.033

Percentile

91.3%

The exif_data_load_data function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

AI Score

6.7

Confidence

Low

EPSS

0.033

Percentile

91.3%