CVE-2005-4676

Exiv2 < 0.9 - Denial of Service via IPTC Metadata Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-4676. PoCs published by Maciek Wierciski.

AI-analyzed exploit summary The provided text describes a denial-of-service vulnerability in Exiv2 due to improper bounds-checking of user-supplied input, leading to an out-of-bounds memory access crash. It affects versions prior to 0.9 and can be exploited locally or remotely depending on the application using the library.

Description

Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, which allows remote attackers to cause a denial of service (application crash) via images with crafted IPTC metadata.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Maciek Wierciski · textdosmultiple
https://www.exploit-db.com/exploits/27140

The provided text describes a denial-of-service vulnerability in Exiv2 due to improper bounds-checking of user-supplied input, leading to an out-of-bounds memory access crash. It affects versions prior to 0.9 and can be exploited locally or remotely depending on the application using the library.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Exiv2 versions prior to 0.9
No auth needed
Prerequisites: Malicious image data processed by an application using the vulnerable Exiv2 library
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Various Sources x_refsource_confirm
http://home.arcor.de/ahuggel/exiv2/changelog.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0345
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18619
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24349
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16400

Scores

EPSS 0.0410
EPSS Percentile 89.7%

Details

Status published
Products (8)
andreas_huggel/exiv2 0.3
andreas_huggel/exiv2 0.4
andreas_huggel/exiv2 0.5
andreas_huggel/exiv2 0.6
andreas_huggel/exiv2 0.6.1
andreas_huggel/exiv2 0.6.2
andreas_huggel/exiv2 0.7
andreas_huggel/exiv2 0.8
Published Dec 31, 2005
Tracked Since Feb 18, 2026