Unrated severityNVD Advisory· Published Nov 20, 2009· Updated Apr 23, 2026
CVE-2009-3895
CVE-2009-3895
Description
Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via an invalid EXIF image. NOTE: some of these details are obtained from third party information.
Affected products
1- cpe:2.3:a:libexif_project:libexif:0.6.18:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- libexif.cvs.sourceforge.net/viewvc/libexif/libexif/NEWSnvdPatch
- secunia.com/advisories/37378nvdVendor Advisory
- www.vupen.com/english/advisories/2009/3243nvdVendor Advisory
- bugs.debian.org/557137nvd
- bugs.gentoo.org/show_bug.cginvd
- sourceforge.net/mailarchive/message.phpnvd
- www.openwall.com/lists/oss-security/2009/11/19/2nvd
- www.osvdb.org/59956nvd
- www.securityfocus.com/bid/37022nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/54275nvd
News mentions
0No linked articles in our index yet.