Lucene search

K
cveMitreCVE-2006-4168
HistoryJun 14, 2007 - 7:30 p.m.

CVE-2006-4168

2007-06-1419:30:00
mitre
web.nvd.nist.gov
38
cve-2006-4168
integer overflow
libexif
exif
buffer overflow
remote attack
denial of service
arbitrary code execution
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.261

Percentile

96.7%

Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow.

Affected configurations

Nvd
Node
libexiflibexifMatch0.6.9
OR
libexiflibexifMatch0.6.11
OR
libexiflibexifMatch0.6.12
OR
libexiflibexifMatch0.6.13
OR
libexiflibexifMatch0.6.14
OR
libexiflibexifMatch0.6.15
VendorProductVersionCPE
libexiflibexif0.6.9cpe:2.3:a:libexif:libexif:0.6.9:*:*:*:*:*:*:*
libexiflibexif0.6.11cpe:2.3:a:libexif:libexif:0.6.11:*:*:*:*:*:*:*
libexiflibexif0.6.12cpe:2.3:a:libexif:libexif:0.6.12:*:*:*:*:*:*:*
libexiflibexif0.6.13cpe:2.3:a:libexif:libexif:0.6.13:*:*:*:*:*:*:*
libexiflibexif0.6.14cpe:2.3:a:libexif:libexif:0.6.14:*:*:*:*:*:*:*
libexiflibexif0.6.15cpe:2.3:a:libexif:libexif:0.6.15:*:*:*:*:*:*:*

References

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.261

Percentile

96.7%