Description: | Description:
The remote host is missing an update to exiv2 announced via advisory USN-655-1.
A security issue affects the following Ubuntu releases:
Ubuntu 7.04 Ubuntu 7.10 Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Details follow:
Meder Kydyraliev discovered that exiv2 did not correctly handle certain EXIF headers. If a user or automated system were tricked into processing a specially crafted image, a remote attacker could cause the application linked against libexiv2 to crash, leading to a denial of service, or possibly executing arbitrary code with user privileges. (CVE-2007-6353)
Joakim Bildrulle discovered that exiv2 did not correctly handle Nikon lens EXIF information. If a user or automated system were tricked into processing a specially crafted image, a remote attacker could cause the application linked against libexiv2 to crash, leading to a denial of service. (CVE-2008-2696)
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 7.04: libexiv2-0.12 0.12-0ubuntu2.1
Ubuntu 7.10: libexiv2-0 0.15-1ubuntu2.1
Ubuntu 8.04 LTS: libexiv2-2 0.16-3ubuntu1.1
After a standard system upgrade you need to restart your session to effect the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-655-1
Risk factor : High
CVSS Score: 7.5
|