libgphoto2是gPhoto开源的一个数码相机访问与控制库。 libgphoto2 2.5.33及之前版本存在安全漏洞,该漏洞源于camlibs/ptp2/ptp-pack.c文件中ptp_unpack_Sony_DPD函数在PTP_DPFF_Enumeration情况下读取2字节枚举计数时未验证缓冲区剩余字节,可能导致越界读取。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gphoto | libgphoto2 | <= 2.5.33 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40340 | 6.1 MEDIUM | libgphoto2 has OOB read in ptp_unpack_OI() in ptp-pack.c via malicious PTP ObjectInfo resp |
| CVE-2026-40333 | 6.1 MEDIUM | libgphoto2 has OOB read in ptp_unpack_EOS_ImageFormat() and ptp_unpack_EOS_CustomFuncEx() |
| CVE-2026-40339 | 5.2 MEDIUM | libgphoto2 has OOB read in ptp_unpack_Sony_DPD() FormFlag parsing in ptp-pack.c |
| CVE-2026-40335 | 5.2 MEDIUM | libgphoto2 has OOB read in ptp_unpack_DPV() UINT128/INT128 handling in ptp-pack.c |
| CVE-2026-40334 | 3.5 LOW | libgphoto2 missing null termination in ptp_unpack_Canon_FE() filename buffer in ptp-pack.c |
| CVE-2026-40341 | 3.5 LOW | libgphoto2 has an OOB Read in ptp_unpack_EOS_FocusInfoEx |
| CVE-2026-40336 | 2.4 LOW | libgphoto2 has memory leak in ptp_unpack_Sony_DPD() secondary enumeration list in ptp-pack |
No comments yet