CVE-2017-7544 PUBLISHED

libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.

EPSS 0.39% · 60.1th percentile

Risk Scores

EPSS Score
0.39%
60.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSlibexif0, 0.6.21-1, 0.6.21-1ubuntu1
Ubuntu:16.04:LTSlibexif0, 0.6.21-2

Timeline

References

Open in Interactive Console →