USN-471-1: libexif vulnerability
11 June 2007
libexif vulnerability
Releases
Details
Victor Stinner discovered that libexif did not correctly validate the
size of some EXIF header fields. By tricking a user into opening an
image with specially crafted EXIF headers, a remote attacker could cause
the application using libexif to crash, resulting in a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 7.04
-
libexif12
-
0.6.13-5ubuntu0.1
Ubuntu 6.10
-
libexif12
-
0.6.13-4ubuntu0.1
Ubuntu 6.06
-
libexif12
-
0.6.12-2ubuntu0.1
After a standard system upgrade you need to restart your session to
effect the necessary changes.