Description: Two vulnerabilities have been reported in libexif, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise an application using the library.
1) An integer overflow error in the "exif_data_load_data_thumbnail()" function in exif-data.c when processing exif image tags can be exploited to cause a memory corruption and may allow execution of arbitrary code via a specially crafted exif file.
2) An infinite recursion error in the "exif_loader_write()" function in exif-loader.c when handling exif image tags can be exploited to cause an application to crash via a specially crafted exif file.
Solution: Fixed in the CVS repository.
Provided and/or discovered by: The vendor credits Meder Kydyraliev, Google Security Team. Reported in a Red Hat advisory.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.