« Volver al listado

CVE-2012-2813

Estado: ModificadaMedia (6.4)—

The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-2813",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "chrome-cve-admin@google.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-07-13T10:34:59.390",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-1255.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://secunia.com/advisories/49988",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://sourceforge.net/mailarchive/message.php?msg_id=29534027",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.debian.org/security/2012/dsa-2559",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/54437",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1513-1",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-1255.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/49988",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/mailarchive/message.php?msg_id=29534027",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2012/dsa-2559",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/54437",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1513-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The exif_convert_utf16_to_utf8 function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image."
    },
    {
      "lang": "es",
      "value": "La función exif_convert_utf16_to_utf8 en exif-entry.c en la biblioteca de análisis de etiquetas EXIF (también conocida como libexif) antes de v0.6.21 permite a atacantes remotos provocar una denegación de servicio (lectura fuera de límites) o, posiblemente, obtener información sensible de la memoria del proceso a través de etiquetas EXIF debidamente modificadas en una imagen."
    }
  ],
  "lastModified": "2026-06-16T23:42:08.830",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7F5BCBB-8E44-48D0-BA9C-92402AF7C857",
              "versionEndIncluding": "0.6.20"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.14:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "292ACF38-49DE-4FDA-BE81-3917A84A85F1"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.15:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F56D8C36-2ADE-41AE-BF65-02BEEBF847D1"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A94B7C3-90F7-45C8-B768-D71E7F552FE9"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.18:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D844FD6-6B88-456C-9BA5-B86CF92823AB"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.19:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3767B157-215E-4F49-A76D-8652ECC11F3F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "chrome-cve-admin@google.com"
}