PDA

View Full Version : USN-478-1: libexif vulnerability



rss-bot
June 27th, 2007, 04:30 AM
Referenced CVEs:
CVE-2006-4168


Description:
================================================== ========= Ubuntu Security Notice USN-478-1 June 26, 2007 libexif vulnerability CVE-2006-4168 ================================================== ========= A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libexif12 0.6.12-2ubuntu0.2 Ubuntu 6.10: libexif12 0.6.13-4ubuntu0.2 Ubuntu 7.04: libexif12 0.6.13-5ubuntu0.2 After a standard system upgrade you need to restart your session to effect the necessary changes. Details follow: Sean Larsson discovered that libexif did not correctly verify the size of EXIF components. By tricking a user into opening an image with specially crafted EXIF headers, a remote attacker could cause the application using libexif to execute arbitrary code with user privileges.





More... (http://www.ubuntu.com/usn/usn-478-1)