CVE-2005-4676
Exiv2 < 0.9 - Denial of Service via IPTC Metadata Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4676. PoCs published by Maciek Wierciski.
AI-analyzed exploit summary The provided text describes a denial-of-service vulnerability in Exiv2 due to improper bounds-checking of user-supplied input, leading to an out-of-bounds memory access crash. It affects versions prior to 0.9 and can be exploited locally or remotely depending on the application using the library.
Description
Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.
Exploits (1)
The provided text describes a denial-of-service vulnerability in Exiv2 due to improper bounds-checking of user-supplied input, leading to an out-of-bounds memory access crash. It affects versions prior to 0.9 and can be exploited locally or remotely depending on the application using the library.