CVE-2005-4676 Information
Feb 14, 2021
cve
Description
Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.
Reference
http://dev.robotbattle.com/mantis/bug_view_advanced_page.php?bug_id=447 http://home.arcor.de/ahuggel/exiv2/changelog.html http://secunia.com/advisories/18619 http://www.securityfocus.com/bid/16400 http://www.vupen.com/english/advisories/2006/0345 https://exchange.xforce.ibmcloud.com/vulnerabilities/24349
Share on: