OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[ GLSA 200706-09 ] libexif: Buffer overflow

From: Raphael Marichez (falcogentoo.org)
Date: Tue Jun 26 2007 - 16:22:02 CDT


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200706-09
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: Normal
     Title: libexif: Buffer overflow
      Date: June 26, 2007
      Bugs: #181922
        ID: 200706-09

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

libexif does not properly handle image EXIF information, possibly
allowing for the execution of arbitrary code.

Background
==========

libexif is a library for parsing, editing and saving EXIF metadata from
images.

Affected packages
=================

    -------------------------------------------------------------------
     Package / Vulnerable / Unaffected
    -------------------------------------------------------------------
  1 media-libs/libexif < 0.6.16 >= 0.6.16

Description
===========

iDefense Labs have discovered that the exif_data_load_data_entry()
function in libexif/exif-data.c improperly handles integer data while
working with an image with many EXIF components, allowing an integer
overflow possibly leading to a heap-based buffer overflow.

Impact
======

An attacker could entice a user of an application making use of a
vulnerable version of libexif to load a specially crafted image file,
possibly resulting in a crash of the application or the execution of
arbitrary code with the rights of the user running the application.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All libexif users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=media-libs/libexif-0.6.16"

References
==========

  [ 1 ] CVE-2006-4168
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4168

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

  http://security.gentoo.org/glsa/glsa-200706-09.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
securitygentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2007 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iQEVAwUBRoGDejvRww8BFPxFAQI3TQf/abZeouCwhMucF//nUXenNE94dMAnBjlM
XIB3XD+3T1ygMJB56NsTXPG3FdjP3T3noZOYAK53J0ZVr7jYh59pFguzPhyPX94L
w0vo1rz49XaPTNy3HIHYMb9hpklVmG2no9DQvDtvHGsq/mZXPAgaAqa7puIvl6ut
ASgvSg72cS+yMLmw2SgKYONbPofu75x9ERsADjptwvz+k6RJAYUxMC8RXqOdmStl
f5LKLhJIGmFjHGpu5KTos2nBw/LEGlTU30gdKIOHpA9qkXOXiANYDks9K88eCCKe
KX4tF3jkBUAaWPHmD7gCfJH1U57SELmnIFmu/mO+GS2eXJhZ8LL83Q==
=GI7V
-----END PGP SIGNATURE-----