USN-91-1: EXIF library vulnerability
8 March 2005
EXIF library vulnerability
Releases
Details
Sylvain Defresne discovered that the EXIF library did not properly
validate the structure of the EXIF tags. By tricking a user to load an
image with a malicious EXIF tag, an attacker could exploit this to
crash the process using the library, or even execute arbitrary code
with the privileges of the process.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 4.10
-
libexif10
-
In general, a standard system update will make all the necessary changes.