This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Aertherwide First view 2007-12-18
Product Exiftags Last view 2024-08-27
Version 0.92 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:aertherwide:exiftags

Activity : Overall

Related : CVE

  Date Alert Description
7.8 2024-08-27 CVE-2024-42851

Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.

5 2007-12-18 CVE-2007-6356

exiftags before 1.01 allows attackers to cause a denial of service (infinite loop) via recursive IFD references in the EXIF data in a JPEG image.

10 2007-12-18 CVE-2007-6355

Integer overflow in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6354.

10 2007-12-18 CVE-2007-6354

Unspecified vulnerability in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6355.

CWE : Common Weakness Enumeration

%idName
33% (1) CWE-787 Out-of-bounds Write
33% (1) CWE-399 Resource Management Errors
33% (1) CWE-189 Numeric Errors

Open Source Vulnerability Database (OSVDB)

id Description
42648 exiftags Unspecified Field Offset Overflow #1
42647 exiftags JPEG Handling EXIF Data IFD References Recursion DoS
42646 exiftags Unspecified Field Offset Overflow #2

OpenVAS Exploits

id Description
2008-09-24 Name : Gentoo Security Advisory GLSA 200712-17 (exiftags)
File : nvt/glsa_200712_17.nasl
2008-04-07 Name : Debian Security Advisory DSA 1533-1 (exiftags)
File : nvt/deb_1533_1.nasl
2008-04-07 Name : Debian Security Advisory DSA 1533-2 (exiftags)
File : nvt/deb_1533_2.nasl

Nessus® Vulnerability Scanner

id Description
2008-03-31 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-1533.nasl - Type: ACT_GATHER_INFO
2007-12-31 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-200712-17.nasl - Type: ACT_GATHER_INFO