CVE-2006-4168

N/A Unknown
Published: June 14, 2007 Modified: April 23, 2026
View on NVD

Description

Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/35379
Source: cve@mitre.org
http://secunia.com/advisories/25642
Source: cve@mitre.org
Patch Vendor Advisory
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=543
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://osvdb.org/35379
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25642
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://secunia.com/advisories/25645
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25674
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25717/
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25746
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25768
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25820
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25842
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25932
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26083
Source: af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-200706-09.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://sourceforge.net/project/shownotes.php?release_id=515385
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.debian.org/security/2007/dsa-1310
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2007:128
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.novell.com/linux/security/advisories/2007_14_sr.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/472046/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/24461
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1018240
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-478-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/2165
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/34851
Source: af854a3a-2127-422b-91ae-364da2661108
https://issues.rpath.com/browse/RPL-1482
Source: af854a3a-2127-422b-91ae-364da2661108
https://rhn.redhat.com/errata/RHSA-2007-0501.html
Source: af854a3a-2127-422b-91ae-364da2661108

54 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
7.5%
92th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

libexif