Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
EXIF库EXIF文件处理整数溢出漏洞
Vulnerability Description
libexif是一个使用C语言编写的函数库,用于从图形文件中读写EXIF元信息。 libexif库在处理畸形格式的EXIF文件时存在漏洞,远程攻击者可能利用此漏洞控制用户机器。 libexif的exif_data_load_data_entry函数在解析包含有大量Exif组件的标签图形时存在整数溢出漏洞。如果用户使用包含有该函数库的应用程序打开了特制的EXIF文件的话,就可能触发堆溢出,导致拒绝服务或执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A