UBUNTU-CVE-2016-6328
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-6328
UBUNTU-CVE-2016-6328
Published: 31 Oct 2018Last Modified: 22 Apr 2026
Upstream:
Aliases:
Summary:
Details: A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metadata, even other applications' private data).
References: https://ubuntu.com/security/CVE-2016-6328, https://ubuntu.com/security/notices/USN-4277-1, https://www.cve.org/CVERecord?id=CVE-2016-6328
Affected packages
Package
Name: libexif
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -0.6.21-1ubuntu1+esm1
Affected versions
0.6.21-1
0.6.21-1ubuntu1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
