USN-91-1: EXIF library vulnerability

8 March 2005

libexif vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 4.10

Software Description

Details

Sylvain Defresne discovered that the EXIF library did not properly validate the structure of the EXIF tags. By tricking a user to load an image with a malicious EXIF tag, an attacker could exploit this to crash the process using the library, or even execute arbitrary code with the privileges of the process.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 4.10
libexif10

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

References