Summary
The remote host is missing an update to exiftags
announced via advisory DSA 1533-2.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201533-2
Insight
Christian Schmid and Meder Kydyraliev (Google Security) discovered a number of vulnerabilities in exiftags, a utility for extracting EXIF metadata from JPEG images. This update merely adds the packages for Debian 3.1 sarge (oldstable) which were missing in the previous DSA.
The Common Vulnerabilities and Exposures project identified the following three problems:
CVE-2007-6354
Inadequate EXIF property validation could lead to invalid memory accesses if executed on a maliciously crafted image, potentially including heap corruption and the execution of arbitrary code.
CVE-2007-6355
Flawed data validation could lead to integer overflows, causing other invalid memory accesses, also with the potential for memory corruption or arbitrary code execution.
CVE-2007-6356
Cyclical EXIF image file directory (IFD) references could cause a denial of service (infinite loop).
For the stable distribution (etch), these problems have been fixed in version 0.98-1.1+etch1.
For the oldstable distribution (sarge), these problems have been fixed in version 0.98-1.1+0sarge1.
For the unstable distribution (sid), these problems have been fixed in version 1.01-0.1.
Severity
Classification
-
CVE CVE-2007-6354, CVE-2007-6355, CVE-2007-6356 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities