Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Libexif ‘exif_entry_get_value’函数整数下溢漏洞
Vulnerability Description
libexif是一个使用C语言编写的函数库,用于从图形文件中读写EXIF元信息。 EXIF Tag Parsing Library (又名libexif) 0.6.20版本中的exif-entry.c中的exif_entry_get_value函数中存在整数下溢漏洞。远程攻击者可利用该漏洞通过包含在EXIF标签格式化期间的特制buffer-size参数的向量,执行任意代码,并导致基于堆的缓冲区溢出。
CVSS Information
N/A
Vulnerability Type
N/A