libexif: An EXIF Tag Parsing Library for Digital Cameras ---------------------------------------------------------------------- File: libexif-0.6.14-22.ppc.rpm Patchrpm: libexif-0.6.14-22.ppc.patch.rpm Version: 0.6.14-22 Size: 460 kB Patchsize: 311 kB Date: Wed 09 Jan 2008 16:21:26 CET Source: libexif-0.6.14-22.src.rpm Security: Yes ---------------------------------------------------------------------- Description: Two bugs in libexif were identified by a Google Security Audit done by Meder Kydyraliev. CVE-2007-6351: Loading EXIF data could be used to cause a infinite recursion and crash CVE-2007-6352: Integer overflows in the thumbnail handler could be used to overflow buffers and potentially execute code or crash a program using libexif.