LWN.net Logo

exiv2: denial of service

Package(s):exiv2 CVE #(s):CVE-2008-2696
Created:October 15, 2008 Updated:October 31, 2008
Description:

From the Ubuntu advisory:

Joakim Bildrulle discovered that exiv2 did not correctly handle Nikon lens EXIF information. If a user or automated system were tricked into processing a specially crafted image, a remote attacker could cause the application linked against libexiv2 to crash, leading to a denial of service. (CVE-2008-2696)

Alerts:
SuSE SUSE-SR:2008:023 2008-10-31
Ubuntu USN-655-1 2008-10-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds