Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-7544

Опубликовано: 21 сент. 2017
Источник: nvd
CVSS3: 9.1
CVSS2: 6.4
EPSS Низкий

Описание

libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*
Версия до 0.6.21 (включая)

EPSS

Процентиль: 62%
0.00436
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-125
CWE-125

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 8 лет назад

libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.

CVSS3: 3.3
redhat
больше 8 лет назад

libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.

CVSS3: 9.1
debian
больше 8 лет назад

libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulner ...

suse-cvrf
около 8 лет назад

Security update for libexif

CVSS3: 9.1
github
больше 3 лет назад

libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.

EPSS

Процентиль: 62%
0.00436
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-125
CWE-125