CVE-2016-6328 - log back

CVE-2016-6328 edited at 20 May 2020 22:01:30
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Information disclosure
Description
+ A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metadata, even other applications' private data).
References
+ https://github.com/libexif/libexif/commit/41bd04234b104312f54d25822f68738ba8d7133d
+ https://github.com/libexif/libexif/commit/435e21f05001fb03f9f186fa7cbc69454afd00d1
+ https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-6328
Notes
CVE-2016-6328 created at 19 May 2020 16:12:27