Unrated severityNVD Advisory· Published Jul 13, 2012· Updated Apr 29, 2026
CVE-2012-2841
CVE-2012-2841
Description
Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.
Affected products
1- cpe:2.3:a:libexif_project:libexif:0.6.20:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- lists.opensuse.org/opensuse-security-announce/2012-07/msg00014.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.htmlnvd
- rhn.redhat.com/errata/RHSA-2012-1255.htmlnvd
- secunia.com/advisories/49988nvd
- sourceforge.net/mailarchive/message.phpnvd
- www.debian.org/security/2012/dsa-2559nvd
- www.securityfocus.com/bid/54437nvd
- www.ubuntu.com/usn/USN-1513-1nvd
News mentions
0No linked articles in our index yet.