View Full Version : USN-478-1: libexif vulnerability

June 27th, 2007, 04:30 AM
Referenced CVEs:

================================================== ========= Ubuntu Security Notice USN-478-1 June 26, 2007 libexif vulnerability CVE-2006-4168 ================================================== ========= A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libexif12 0.6.12-2ubuntu0.2 Ubuntu 6.10: libexif12 0.6.13-4ubuntu0.2 Ubuntu 7.04: libexif12 0.6.13-5ubuntu0.2 After a standard system upgrade you need to restart your session to effect the necessary changes. Details follow: Sean Larsson discovered that libexif did not correctly verify the size of EXIF components. By tricking a user into opening an image with specially crafted EXIF headers, a remote attacker could cause the application using libexif to execute arbitrary code with user privileges.

More... (http://www.ubuntu.com/usn/usn-478-1)