EXIF Library EXIF标签解析未明内存损坏漏洞

漏洞信息详情

EXIF Library EXIF标签解析未明内存损坏漏洞

漏洞简介

EXIF library (libexif) 0.6.9中存在缓冲区溢出,系统未能正确地验证EXIF标签结构,远程攻击者可以通过一个带有特制EXIF标签的JPEG图像来发起拒绝服务攻击(应用程序崩溃)并可能执行任意代码。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

libexif libexif 0.5.12

Fedora libexif-0.5.12-2.2.i386.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora libexif-0.5.12-2.2.x86_64.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora libexif-0.5.12-3.1.i386.rpm

RedHat Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

Fedora libexif-0.5.12-3.1.x86_64.rpm

RedHat Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

Fedora libexif-debuginfo-0.5.12-2.2.i386.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora libexif-debuginfo-0.5.12-2.2.x86_64.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora libexif-debuginfo-0.5.12-3.1.i386.rpm

RedHat Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

Fedora libexif-debuginfo-0.5.12-3.1.x86_64.rpm

RedHat Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

Fedora libexif-devel-0.5.12-2.2.i386.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora libexif-devel-0.5.12-2.2.x86_64.rpm

RedHat Fedora Core 2

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

Fedora libexif-devel-0.5.12-3.1.i386.rpm

RedHat Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

Fedora libexif-devel-0.5.12-3.1.x86_64.rpm

RedHat Fedora Core 3

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/

Mandrake lib64exif9-0.5.12-3.1.100mdk.amd64.rpm

Mandrake Linux 10.0/AMD64

http://www.mandrakesecure.net/en/ftp.php

Mandrake lib64exif9-0.5.12-3.1.101mdk.x86_64.rpm

Mandrake Linux 10.1/x86_64

http://www.mandrakesecure.net/en/ftp.php

Mandrake lib64exif9-0.5.12-3.1.C30mdk.x86_64.rpm

Mandrake Corporate Server 3.0/x86_64

http://www.mandrakesecure.net/en/ftp.php

Mandrake lib64exif9-devel-0.5.12-3.1.100mdk.amd64.rpm

Mandrake Linux 10.0/AMD64

http://www.mandrakesecure.net/en/ftp.php

Mandrake lib64exif9-devel-0.5.12-3.1.101mdk.x86_64.rpm

Mandrake Linux 10.1/x86_64

http://www.mandrakesecure.net/en/ftp.php

Mandrake lib64exif9-devel-0.5.12-3.1.C30mdk.x86_64.rpm

Mandrake Corporate Server 3.0/x86_64

http://www.mandrakesecure.net/en/ftp.php

Mandrake libexif9-0.5.12-3.1.100mdk.i586.rpm

Mandrake Linux 10.0

http://www.mandrakesecure.net/en/ftp.php

Mandrake libexif9-0.5.12-3.1.101mdk.i586.rpm

Mandrake Linux 10.1

http://www.mandrakesecure.net/en/ftp.php

Mandrake libexif9-0.5.12-3.1.C30mdk.i586.rpm

Mandrake Corporate Server 3.0

http://www.mandrakesecure.net/en/ftp.php

Mandrake libexif9-devel-0.5.12-3.1.100mdk.i586.rpm

Mandrake Linux 10.0

http://www.mandrakesecure.net/en/ftp.php

Mandrake libexif9-devel-0.5.12-3.1.101mdk.i586.rpm

Mandrake Linux 10.1

http://www.mandrakesecure.net/en/ftp.php

Mandrake libexif9-devel-0.5.12-3.1.C30mdk.i586.rpm

Mandrake Corporate Server 3.0

http://www.mandrakesecure.net/en/ftp.php

libexif libexif 0.6.9

Ubuntu libexif-dev_0.6.9-1ubuntu0.1_amd64.deb

Ubuntu 4.10 (Warty Warthog)

http://security.ubuntu.com/ubuntu/pool/main/libe/libexif/libexif-dev_0 .6.9-1ubuntu0.1_amd64.deb

Ubuntu libexif-dev_0.6.9-1ubuntu0.1_i386.deb

Ubuntu 4.10 (Warty Warthog)

http://security.ubuntu.com/ubuntu/pool/main/libe/libexif/libexif-dev_0 .6.9-1ubuntu0.1_i386.deb

Ubuntu libexif-dev_0.6.9-1ubuntu0.1_powerpc.deb

Ubuntu 4.10 (Warty Warthog)

http://security.ubuntu.com/ubuntu/pool/main/libe/libexif/libexif-dev_0 .6.9-1ubuntu0.1_powerpc.deb

Ubuntu libexif10_0.6.9-1ubuntu0.1_amd64.deb

Ubuntu 4.10 (Warty Warthog)

http://security.ubuntu.com/ubuntu/pool/main/libe/libexif/libexif10_0.6 .9-1ubuntu0.1_amd64.deb

Ubuntu libexif10_0.6.9-1ubuntu0.1_i386.deb

Ubuntu 4.10 (Warty Warthog)

http://security.ubuntu.com/ubuntu/pool/main/libe/libexif/libexif10_0.6 .9-1ubuntu0.1_i386.deb

Ubuntu libexif10_0.6.9-1ubuntu0.1_powerpc.deb

Ubuntu 4.10 (Warty Warthog)

http://security.ubuntu.com/ubuntu/pool/main/l

参考网址

来源: MISC

链接:https://bugzilla.ubuntu.com/show_bug.cgi?id=7152

来源: GENTOO

名称: GLSA-200503-17

链接:http://www.gentoo.org/security/en/glsa/glsa-200503-17.xml

来源: DEBIAN

名称: DSA-709

链接:http://www.debian.org/security/2005/dsa-709

来源: SECTRACK

名称: 1013398

链接:http://securitytracker.com/id?1013398

来源: UBUNTU

名称: USN-91-1

链接:http://www.ubuntulinux.org/support/documentation/usn/usn-91-1

来源: REDHAT

名称: RHSA-2005:300

链接:http://www.redhat.com/support/errata/RHSA-2005-300.html

来源: VUPEN

名称: ADV-2005-2565

链接:http://www.frsirt.com/english/advisories/2005/2565

来源: VUPEN

名称: ADV-2005-0240

链接:http://www.frsirt.com/english/advisories/2005/0240

来源: SUNALERT

名称: 102041

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-102041-1

来源: SECUNIA

名称: 17705

链接:http://secunia.com/advisories/17705

来源: MANDRAKE

名称: MDKSA-2005:064

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:064

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享