Package: libexif12
Version: 0.6.13-5
Severity: grave
Tags: security
Justification: user security hole

CVE-2006-4168:
"Integer overflow in the exif_data_load_data_entry function in
libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to
cause a denial of service (application crash) or execute arbitrary code
via an image with many EXIF components, which triggers a heap-based
buffer overflow."

This is fixed in 0.6.16, see
http://sourceforge.net/project/shownotes.php?release_id=515385


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to