Division by zero in libexif - CVE-2012-2837
Published: July 26, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to divide-by-zero error within the mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library. A remote attacker can perform a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags.
Affected software
Gentoo Linux
Amazon Linux AMI
SUSE Linux
Slackware Linux
libexif (Alpine package)
How to mitigate CVE-2012-2837
libexif (Alpine package) - update to 0.6.21-r0
External References
- http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.html
- http://rhn.redhat.com/errata/RHSA-2012-1255.html
- http://secunia.com/advisories/49988
- http://sourceforge.net/mailarchive/message.php?msg_id=29534027
- http://www.debian.org/security/2012/dsa-2559
- http://www.securityfocus.com/bid/54437
- http://www.ubuntu.com/usn/USN-1513-1