« Volver al listado

CVE-2012-2837

Estado: ModificadaMedia (5)—

The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-2837",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "chrome-cve-admin@google.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-07-13T10:34:59.513",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00014.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-1255.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://secunia.com/advisories/49988",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://sourceforge.net/mailarchive/message.php?msg_id=29534027",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.debian.org/security/2012/dsa-2559",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/54437",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1513-1",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00014.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-1255.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/49988",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/mailarchive/message.php?msg_id=29534027",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2012/dsa-2559",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/54437",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1513-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-189"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The mnote_olympus_entry_get_value function in olympus/mnote-olympus-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (divide-by-zero error) via an image with crafted EXIF tags that are not properly handled during the formatting of EXIF maker note tags."
    },
    {
      "lang": "es",
      "value": "La función mnote_olympus_entry_get_value en Olympus/mNote-olympus-entry.c en la biblioteca de análisis de etiquetas EXIF (también conocido como libexif) antes de v0.6.21 permite a atacantes remotos causar una denegación de servicio (división por error cero) a través de una imagen con etiquetas EXIF modificadas que no se manejan correctamente durante el formateo de etiquetas de notas EXIF."
    }
  ],
  "lastModified": "2026-06-16T23:42:11.520",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7F5BCBB-8E44-48D0-BA9C-92402AF7C857",
              "versionEndIncluding": "0.6.20"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.14:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "292ACF38-49DE-4FDA-BE81-3917A84A85F1"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.15:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F56D8C36-2ADE-41AE-BF65-02BEEBF847D1"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A94B7C3-90F7-45C8-B768-D71E7F552FE9"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.18:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D844FD6-6B88-456C-9BA5-B86CF92823AB"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.19:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3767B157-215E-4F49-A76D-8652ECC11F3F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "chrome-cve-admin@google.com"
}