Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.60360
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1487-1)
Summary:The remote host is missing an update for the Debian 'libexif' package(s) announced via the DSA-1487-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'libexif' package(s) announced via the DSA-1487-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been discovered in the EXIF parsing code of the libexif library, which can lead to denial of service or the execution of arbitrary code if a user is tricked into opening a malformed image. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2007-2645

Victor Stinner discovered an integer overflow, which may result in denial of service or potentially the execution of arbitrary code.

CVE-2007-6351

Meder Kydyraliev discovered an infinite loop, which may result in denial of service.

CVE-2007-6352

Victor Stinner discovered an integer overflow, which may result in denial of service or potentially the execution of arbitrary code.

This update also fixes two potential NULL pointer deferences.

For the old stable distribution (sarge), these problems have been fixed in 0.6.9-6sarge2.

For the stable distribution (etch), these problems have been fixed in version 0.6.13-5etch2.

We recommend that you upgrade your libexif packages.

Affected Software/OS:
'libexif' package(s) on Debian 3.1, Debian 4.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-2645
BugTraq ID: 23927
http://www.securityfocus.com/bid/23927
Bugtraq: 20070604 FLEA-2007-0024-1: libexif (Google Search)
http://www.securityfocus.com/archive/1/470502/100/100/threaded
Debian Security Information: DSA-1487 (Google Search)
http://www.debian.org/security/2008/dsa-1487
http://security.gentoo.org/glsa/glsa-200706-01.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:118
http://sourceforge.net/tracker/index.php?func=detail&aid=1716196&group_id=12272&atid=112272
http://osvdb.org/35978
http://secunia.com/advisories/25235
http://secunia.com/advisories/25540
http://secunia.com/advisories/25569
http://secunia.com/advisories/25599
http://secunia.com/advisories/25621
http://secunia.com/advisories/25932
http://secunia.com/advisories/26083
http://secunia.com/advisories/28776
SuSE Security Announcement: SUSE-SA:2007:039 (Google Search)
http://www.novell.com/linux/security/advisories/2007_39_libexif.html
SuSE Security Announcement: SUSE-SR:2007:014 (Google Search)
http://www.novell.com/linux/security/advisories/2007_14_sr.html
http://www.ubuntu.com/usn/usn-471-1
http://www.vupen.com/english/advisories/2007/1761
XForce ISS Database: libexif-exifdataloaddata-integer-overflow(34233)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34233
Common Vulnerability Exposure (CVE) ID: CVE-2007-6351
BugTraq ID: 26976
http://www.securityfocus.com/bid/26976
Bugtraq: 20080105 rPSA-2008-0006-1 libexif (Google Search)
http://www.securityfocus.com/archive/1/485822/100/0/threaded
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00597.html
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00626.html
http://security.gentoo.org/glsa/glsa-200712-15.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:005
https://bugzilla.redhat.com/show_bug.cgi?id=425551
http://osvdb.org/42652
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9420
http://www.redhat.com/support/errata/RHSA-2007-1165.html
http://www.securitytracker.com/id?1019124
http://secunia.com/advisories/28076
http://secunia.com/advisories/28127
http://secunia.com/advisories/28195
http://secunia.com/advisories/28266
http://secunia.com/advisories/28346
http://secunia.com/advisories/28400
http://secunia.com/advisories/28636
http://secunia.com/advisories/32274
SuSE Security Announcement: SUSE-SR:2008:002 (Google Search)
http://www.novell.com/linux/security/advisories/suse_security_summary_report.html
http://www.ubuntu.com/usn/usn-654-1
http://www.vupen.com/english/advisories/2007/4278
XForce ISS Database: libexif-exifloaderwrit-dos(39166)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39166
Common Vulnerability Exposure (CVE) ID: CVE-2007-6352
BugTraq ID: 26942
http://www.securityfocus.com/bid/26942
http://osvdb.org/42653
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11029
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4814
http://www.redhat.com/support/errata/RHSA-2007-1166.html
http://secunia.com/advisories/29381
http://sunsolve.sun.com/search/document.do?assetkey=1-26-234701-1
http://www.vupen.com/english/advisories/2008/0947/references
XForce ISS Database: libexif-exifdataloaddatathumbnail-bo(39167)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39167
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.