Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-3895
HistoryNov 20, 2009 - 12:00 a.m.

CVE-2009-3895

2009-11-2000:00:00
ubuntu.com
ubuntu.com
15

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.051

Percentile

93.0%

Heap-based buffer overflow in the exif_entry_fix function (aka the tag
fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote
attackers to cause a denial of service or possibly execute arbitrary code
via an invalid EXIF image. NOTE: some of these details are obtained from
third party information.

Bugs

Notes

Author Note
mdeslaur upstream advisory says only 0.6.18 is vulnerable

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.051

Percentile

93.0%