CVE-2007-6353

Publication date 19 December 2007

Last updated 24 July 2024


Ubuntu priority

Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.

Status

Package Ubuntu Release Status
exiv2 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Fixed 0.15-1ubuntu2.1
7.04 feisty
Fixed 0.12-0ubuntu2.1
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-655-1
    • exiv2 vulnerabilities
    • 15 October 2008

Other references