Skip to navigation

Security Advisory Moderate: libexif security update

Advisory: RHSA-2007:1165-4
Type: Security Advisory
Severity: Moderate
Issued on: 2007-12-19
Last updated on: 2007-12-19
Affected Products: RHEL Desktop Workstation (v. 5 client)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux Desktop (v. 5 client)
Red Hat Enterprise Linux EUS (v. 5.1.z server)
CVEs (cve.mitre.org): CVE-2007-6351
CVE-2007-6352

Details

Updated libexif packages that fix several security issues are now available
for Red Hat Enterprise Linux 5.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

The libexif packages contain the Exif library. Exif is an image file format
specification that enables metadata tags to be added to existing JPEG, TIFF
and RIFF files. The Exif library makes it possible to parse an Exif file
and read this metadata.

An infinite recursion flaw was found in the way libexif parses Exif image
tags. If a victim opens a carefully crafted Exif image file, it could cause
the application linked against libexif to crash. (CVE-2007-6351)

An integer overflow flaw was found in the way libexif parses Exif image
tags. If a victim opens a carefully crafted Exif image file, it could cause
the application linked against libexif to execute arbitrary code, or crash.
(CVE-2007-6352)

Users of libexif are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

RHEL Desktop Workstation (v. 5 client)

SRPMS:
libexif-0.6.13-4.0.2.el5_1.1.src.rpm
File outdated by:  RHSA-2012:1255
    MD5: 405b067a3ff329fd2f73b4edfd767837
 
IA-32:
libexif-devel-0.6.13-4.0.2.el5_1.1.i386.rpm
File outdated by:  RHSA-2012:1255
    MD5: eccd0c4354faa72f1aac98e074c53b4e
 
x86_64:
libexif-devel-0.6.13-4.0.2.el5_1.1.i386.rpm
File outdated by:  RHSA-2012:1255
    MD5: eccd0c4354faa72f1aac98e074c53b4e
libexif-devel-0.6.13-4.0.2.el5_1.1.x86_64.rpm
File outdated by:  RHSA-2012:1255
    MD5: a4cd77aa35f9c6e302399e094ca66fef
 
Red Hat Enterprise Linux (v. 5 server)

SRPMS:
libexif-0.6.13-4.0.2.el5_1.1.src.rpm
File outdated by:  RHSA-2012:1255
    MD5: 405b067a3ff329fd2f73b4edfd767837
 
IA-32:
libexif-0.6.13-4.0.2.el5_1.1.i386.rpm
File outdated by:  RHSA-2012:1255
    MD5: 5f5e2fdebf5c7aeb88c4d25ce887edf3
libexif-devel-0.6.13-4.0.2.el5_1.1.i386.rpm
File outdated by:  RHSA-2012:1255
    MD5: eccd0c4354faa72f1aac98e074c53b4e
 
IA-64:
libexif-0.6.13-4.0.2.el5_1.1.ia64.rpm
File outdated by:  RHSA-2012:1255
    MD5: d82e96851e21bad167757e92e702904f
libexif-devel-0.6.13-4.0.2.el5_1.1.ia64.rpm
File outdated by:  RHSA-2012:1255
    MD5: 5e4041135eab0541826dd5332c2114a3
 
PPC:
libexif-0.6.13-4.0.2.el5_1.1.ppc.rpm
File outdated by:  RHSA-2012:1255
    MD5: 1045dc0f0638a436e5fb27d46a7ac953
libexif-0.6.13-4.0.2.el5_1.1.ppc64.rpm
File outdated by:  RHSA-2012:1255
    MD5: 78b8320d53f0e730eb9a7403e132605a
libexif-devel-0.6.13-4.0.2.el5_1.1.ppc.rpm
File outdated by:  RHSA-2012:1255
    MD5: 70db0f13504d616e7cc33f38b4a308ca
libexif-devel-0.6.13-4.0.2.el5_1.1.ppc64.rpm
File outdated by:  RHSA-2012:1255
    MD5: 5aa61322b25614936b3e0af6dbdd0770
 
s390x:
libexif-0.6.13-4.0.2.el5_1.1.s390.rpm
File outdated by:  RHSA-2012:1255
    MD5: a4ce630587f200dac5017132df1b32bd
libexif-0.6.13-4.0.2.el5_1.1.s390x.rpm
File outdated by:  RHSA-2012:1255
    MD5: e4e24274f53f54eafdab963c6827d26e
libexif-devel-0.6.13-4.0.2.el5_1.1.s390.rpm
File outdated by:  RHSA-2012:1255
    MD5: 12a3e54a8e9d55063f504c68b0aee802
libexif-devel-0.6.13-4.0.2.el5_1.1.s390x.rpm
File outdated by:  RHSA-2012:1255
    MD5: 2caf7997904ed6242a03c86522bdabfc
 
x86_64:
libexif-0.6.13-4.0.2.el5_1.1.i386.rpm
File outdated by:  RHSA-2012:1255
    MD5: 5f5e2fdebf5c7aeb88c4d25ce887edf3
libexif-0.6.13-4.0.2.el5_1.1.x86_64.rpm
File outdated by:  RHSA-2012:1255
    MD5: 91d485dd3c59491db18592d70a25a59a
libexif-devel-0.6.13-4.0.2.el5_1.1.i386.rpm
File outdated by:  RHSA-2012:1255
    MD5: eccd0c4354faa72f1aac98e074c53b4e
libexif-devel-0.6.13-4.0.2.el5_1.1.x86_64.rpm
File outdated by:  RHSA-2012:1255
    MD5: a4cd77aa35f9c6e302399e094ca66fef
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
libexif-0.6.13-4.0.2.el5_1.1.src.rpm
File outdated by:  RHSA-2012:1255
    MD5: 405b067a3ff329fd2f73b4edfd767837
 
IA-32:
libexif-0.6.13-4.0.2.el5_1.1.i386.rpm
File outdated by:  RHSA-2012:1255
    MD5: 5f5e2fdebf5c7aeb88c4d25ce887edf3
 
x86_64:
libexif-0.6.13-4.0.2.el5_1.1.i386.rpm
File outdated by:  RHSA-2012:1255
    MD5: 5f5e2fdebf5c7aeb88c4d25ce887edf3
libexif-0.6.13-4.0.2.el5_1.1.x86_64.rpm
File outdated by:  RHSA-2012:1255
    MD5: 91d485dd3c59491db18592d70a25a59a
 
Red Hat Enterprise Linux EUS (v. 5.1.z server)

SRPMS:
libexif-0.6.13-4.0.2.el5_1.1.src.rpm
File outdated by:  RHSA-2012:1255
    MD5: 405b067a3ff329fd2f73b4edfd767837
 
IA-32:
libexif-0.6.13-4.0.2.el5_1.1.i386.rpm     MD5: 5f5e2fdebf5c7aeb88c4d25ce887edf3
libexif-devel-0.6.13-4.0.2.el5_1.1.i386.rpm     MD5: eccd0c4354faa72f1aac98e074c53b4e
 
IA-64:
libexif-0.6.13-4.0.2.el5_1.1.ia64.rpm     MD5: d82e96851e21bad167757e92e702904f
libexif-devel-0.6.13-4.0.2.el5_1.1.ia64.rpm     MD5: 5e4041135eab0541826dd5332c2114a3
 
PPC:
libexif-0.6.13-4.0.2.el5_1.1.ppc.rpm     MD5: 1045dc0f0638a436e5fb27d46a7ac953
libexif-0.6.13-4.0.2.el5_1.1.ppc64.rpm     MD5: 78b8320d53f0e730eb9a7403e132605a
libexif-devel-0.6.13-4.0.2.el5_1.1.ppc.rpm     MD5: 70db0f13504d616e7cc33f38b4a308ca
libexif-devel-0.6.13-4.0.2.el5_1.1.ppc64.rpm     MD5: 5aa61322b25614936b3e0af6dbdd0770
 
s390x:
libexif-0.6.13-4.0.2.el5_1.1.s390.rpm     MD5: a4ce630587f200dac5017132df1b32bd
libexif-0.6.13-4.0.2.el5_1.1.s390x.rpm     MD5: e4e24274f53f54eafdab963c6827d26e
libexif-devel-0.6.13-4.0.2.el5_1.1.s390.rpm     MD5: 12a3e54a8e9d55063f504c68b0aee802
libexif-devel-0.6.13-4.0.2.el5_1.1.s390x.rpm     MD5: 2caf7997904ed6242a03c86522bdabfc
 
x86_64:
libexif-0.6.13-4.0.2.el5_1.1.i386.rpm     MD5: 5f5e2fdebf5c7aeb88c4d25ce887edf3
libexif-0.6.13-4.0.2.el5_1.1.x86_64.rpm     MD5: 91d485dd3c59491db18592d70a25a59a
libexif-devel-0.6.13-4.0.2.el5_1.1.i386.rpm     MD5: eccd0c4354faa72f1aac98e074c53b4e
libexif-devel-0.6.13-4.0.2.el5_1.1.x86_64.rpm     MD5: a4cd77aa35f9c6e302399e094ca66fef
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

425551 - CVE-2007-6351 libexif infinite recursion flaw (DoS)
425561 - CVE-2007-6352 libexif integer overflow


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/