CVE-2005-0664
libexif - buffer overflow
EPSS 3.1%
Description
Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag.
How to fix CVE-2005-0664
To remediate CVE-2005-0664, upgrade the affected package to a fixed version below.
- Debian/libexif—upgrade to 0.6.9-5 or later
- Debian/libexif—upgrade to 0.5.0-1woody1 or later
Is CVE-2005-0664 being exploited?
Low — EPSS is 3.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.6.9-5
- from 0, < 0.5.0-1woody1