Описание
Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.
Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2005-4676
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24349
- http://dev.robotbattle.com/mantis/bug_view_advanced_page.php?bug_id=447
- http://home.arcor.de/ahuggel/exiv2/changelog.html
- http://secunia.com/advisories/18619
- http://www.securityfocus.com/bid/16400
- http://www.vupen.com/english/advisories/2006/0345
EPSS
CVE ID
Связанные уязвимости
Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.
Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null termi ...
EPSS