>> Exiv2 "setDataArea()" EXIF Data Parsing Integer Overflow Vulnerability
Title : Exiv2 "setDataArea()" EXIF Data Parsing Integer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-4252 CVE ID : CVE-2007-6353
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-18
Technical Description
A vulnerability has been identified in Exiv2, which could be exploited by attackers to cause a denial of service or compromise an affected system. This issue is caused by integer overflow errors in the "setDataArea()" functions within "src/exif.cpp" when processing malformed EXIF data, which could be exploited by attackers to crash a vulnerable application or execute arbitrary code.