Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.
Vector
NETWORK
Complexity
LOW
Authentication
NONE
Confidentiality
PARTIAL
Integrity
NONE
Availability
PARTIAL
Advisory | Patch | Confirmed | Link |
---|---|---|---|
MDVSA-2012:107 | |||
[libexif-devel] 20120712 libexif project security adviso... | |||
54437 |