(Sun Issues Fix for Solaris) libexif Buffer Overflow in Processing EXIF Headers May Let Remote Users Crash the Application
|
|
SecurityTracker Alert ID: 1015263 |
|
SecurityTracker URL: http://securitytracker.com/id/1015263
|
|
CVE Reference:
CVE-2005-0664
(Links to External Site)
|
Updated: Jun 13 2007
|
Original Entry Date: Nov 24 2005
|
Impact:
Denial of service via network, Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 0.6.9 and prior versions
|
Description:
A buffer overflow vulnerability was reported in libexif. A remote user may be able to cause a target user's application to crash or execute arbitrary code.
The exif library does not properly validate user-supplied input in several places. A remote user can create a specially crafted JPEG image with invalid EXIF header data. When the image is loaded by the target user's application that uses libexif, the application may crash or potentially execute arbitrary code.
The flaw resides in 'exif-data.c'.
Sylvain Defresne discovered this vulnerability.
|
Impact:
A remote user can create an image file that, when loaded by the target user's application, will cause the application to crash or potentially execute arbitrary code.
|
Solution:
Sun has issued the following fixes:
SPARC Platform
* Solaris 10 without patch 121095-01
x86 Platform
* Java Desktop System (JDS) Release 2 (for Solaris 9) without patch 121093-01
* Solaris 10 without patch 121096-01
Linux
* Sun Java Desktop System (JDS) release 2003
* Sun Java Desktop System (JDS) Release 2 without the updated RPMs (patch-9996)
Solaris 8 and Solaris 9 are not affected.
Sun's advisory is available at:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102041-1
|
Vendor URL: sourceforge.net/projects/libexif/ (Links to External Site)
|
Cause:
Boundary error
|
Underlying OS:
UNIX (Solaris - SunOS)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Thu, 24 Nov 2005 01:29:13 -0500
Subject: Security Vulnerability in the libexif JPEG Image Processing Library
|
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102041-1
CAN-2005-0664 CVE-2005-0664
|
|