Submitted by KeesCook on Mon, 2007-06-11 22:21
Referenced CVEs:
CVE-2007-2645
Description:
===========================================================
Ubuntu Security Notice USN-471-1 June 11, 2007
libexif vulnerability
CVE-2007-2645
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libexif12 0.6.12-2ubuntu0.1
Ubuntu 6.10:
libexif12 0.6.13-4ubuntu0.1
Ubuntu 7.04:
libexif12 0.6.13-5ubuntu0.1
After a standard system upgrade you need to restart your session to
effect the necessary changes.
Details follow:
Victor Stinner discovered that libexif did not correctly validate the
size of some EXIF header fields. By tricking a user into opening an
image with specially crafted EXIF headers, a remote attacker could cause
the application using libexif to crash, resulting in a denial of service.


