Package: exiftags
Severity: grave
Tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for exiftags.

CVE-2007-6356[0]:
| exiftags before 1.01 allows attackers to cause a denial of service
| (infinite loop) via recursive IFD references in the EXIF data in a
| JPEG image.

CVE-2007-6355[1]:
| Unspecified vulnerability in exiftags before 1.01 has 
| unknown impact and attack vectors, resulting from a "field 
| offset overflow," a different vulnerability than 
| CVE-2007-6354.

If you fix this vulnerability please also include the CVE id
in your changelog entry.

For further information:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6356
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6355

Kind regards
Nico

-- 
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgpouDCSOObuf.pgp
Description: PGP signature

Reply via email to