« Volver al listado

CVE-2012-2836

Estado: ModificadaMedia (6.4)—

The exif_data_load_data function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-2836",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "chrome-cve-admin@google.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-07-13T10:34:59.467",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00014.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-1255.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://secunia.com/advisories/49988",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://sourceforge.net/mailarchive/message.php?msg_id=29534027",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.debian.org/security/2012/dsa-2559",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/54437",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1513-1",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00014.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00015.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-1255.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/49988",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/mailarchive/message.php?msg_id=29534027",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2012/dsa-2559",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/54437",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1513-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The exif_data_load_data function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image."
    },
    {
      "lang": "es",
      "value": "La función exif_data_load_data en Exif-data.c en la biblioteca de análisis de etiquetas EXIF (también Conocida como libexif) antes de v0.6.21 permite a atacantes remotos provocar una denegación de servicio (Lectura fuera de límites) o, posiblemente, obtener información sensible de la memoria del proceso a través de etiquestas EXIF en una imagen."
    }
  ],
  "lastModified": "2026-06-16T23:42:11.407",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7F5BCBB-8E44-48D0-BA9C-92402AF7C857",
              "versionEndIncluding": "0.6.20"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.14:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "292ACF38-49DE-4FDA-BE81-3917A84A85F1"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.15:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F56D8C36-2ADE-41AE-BF65-02BEEBF847D1"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A94B7C3-90F7-45C8-B768-D71E7F552FE9"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.18:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D844FD6-6B88-456C-9BA5-B86CF92823AB"
            },
            {
              "criteria": "cpe:2.3:a:libexif_project:libexif:0.6.19:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3767B157-215E-4F49-A76D-8652ECC11F3F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "chrome-cve-admin@google.com"
}