Exiv2 Library IPTC Metadata sscanf() denial of service

exiv2-iptc-metadata-dos (24349) The risk level is classified as LowLow Risk

Description:

Exiv2 is vulnerable to a denial of service, caused by a buffer overflow in the sscanf() function. By creating an image file containing specially-crafted IPTC Metadata, and then convincing a user to open the file, an attacker could overflow a buffer and cause the application linked to the vulnerable Exiv2 library to crash.

Platforms Affected:

  • Andreas Huggel, Exiv2 0.8 and prior

Remedy:

Upgrade to the latest version of Exiv2 (0.9 or later), available from the Exiv2 Web page. See References.

Consequences:

Denial of Service

References:

Reported:

Jan 26, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page