>> Sun Solaris and Java Desktop System Libexif Library Vulnerability
Title : Sun Solaris and Java Desktop System Libexif Library Vulnerability VUPEN ID : VUPEN/ADV-2005-2565 CVE ID : CVE-2005-0664
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-11-24
Technical Description
A vulnerability has been identified in Sun Solaris and Sun Java Desktop System, which may be exploited by attackers to execute arbitrary commands or cause a denial of service. This flaw is due to a buffer overflow error in the Libexif library that does not properly validate the structure of the EXIF tags, which could be exploited by a remote attacker to execute arbitrary code with the privileges of a local user who opens a specially crafted JPEG image. For additional information, see : VUPEN/ADV-2005-0240