iDefense Security Advisory 06.13.07 – Remote exploitation of a integer overflow vulnerability in libexif, as included in various vendors’ operating system distributions, could allow attackers to crash the process or execute arbitrary code. The problem exists while parsing a tagged image with a large number of Exif components. Applications using this library are susceptible to a heap overflow when an integer overflow is triggered in the exif_data_load_data_entry function. iDefense confirmed the existence of this vulnerability in versions 0.6.13 through 0.6.15 of libexif.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/57170/06.13.07-1.txt
Source: https://packetstormsecurity.com/files/57170/iDEFENSE-Security-Advisory-2007-06-13.1.html

