Upstream information
Description
Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted EXIF data, involving the (1) doff or (2) s variable.NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 281287 SUSE Security Advisories:- SUSE-SA:2007:039, published Tue, 03 Jul 2007 17:00:00 +0000
- SUSE-SR:2007:014, published Fri, 20 Jul 2007 12:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE LINUX 10.1 |
| |
| SUSE LINUX 10.0 |
| |
| SUSE LINUX 10.0 |
| |
| Novell Linux Desktop 9 for x86_64 |
| ul1.s390 sles9-oes.x86 slrs8.x86 core9.s390 YOU Patch Nr: 11555 |
| Novell Linux Desktop 9 for x86 Open Enterprise Server |
| ul1.s390 sles9-oes.x86 slrs8.x86 core9.s390 YOU Patch Nr: 11555 |
| SUSE LINUX Retail Solution 8 SuSE Linux Desktop 1.0 SuSE Linux Enterprise Server 8 for AMD64 SuSE Linux Enterprise Server 8 for IBM iSeries and IBM pSeries SuSE Linux Enterprise Server 8 for IBM zSeries SuSE Linux Enterprise Server 8 for IPF SuSE Linux Openexchange Server 4 SuSE Linux School Server for i386 SuSE Linux Standard Server 8 UnitedLinux 1.0 |
| ul1.s390 sles9-oes.x86 slrs8.x86 core9.s390 YOU Patch Nr: 11555 |
| SUSE LINUX 10.1 |
|
