CVE-2017-7544
libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.27%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 3.27% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- libexif project/libexif
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html
- https://lists.debian.org/debian-lts-announce/2020/05/msg00016.html
- https://sourceforge.net/p/libexif/bugs/130/Exploit, Third Party Advisory
- https://usn.ubuntu.com/4277-1/
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00017.html
- https://lists.debian.org/debian-lts-announce/2020/05/msg00016.html
- https://sourceforge.net/p/libexif/bugs/130/Exploit, Third Party Advisory
- https://usn.ubuntu.com/4277-1/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.