Vulnerabilities > CVE-2005-4676 - Unspecified vulnerability in Andreas Huggel Exiv2

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
andreas-huggel
exploit available

Summary

Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.

Exploit-Db

descriptionExiv2 Corrupted EXIF Data Denial Of Service Vulnerability. CVE-2005-4676. Dos exploits for multiple platform
idEDB-ID:27140
last seen2016-02-03
modified2006-01-26
published2006-01-26
reporterMaciek Wierciski
sourcehttps://www.exploit-db.com/download/27140/
titleExiv2 - Corrupted EXIF Data Denial of Service Vulnerability