← Vulnerability feed

Vulnerability record · CVE-2007-6352 · published 20 December 2007

CVE-2007-6352: Libexif vulnerability

LLibexif · Libexif

Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.

6.8 CVSS 2.0 Medium EPSS 2.7% · top 14.5% CWE-189 · CWE-189
6.8CVSS 2.0 base score
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
68References
16 Jun 2026Last modified by NVD

Description

Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.gentoo.org/show_bug.cgi?id=202350
http://osvdb.org/42653
http://secunia.com/advisories/28076 Vendor Advisory
http://secunia.com/advisories/28127 Vendor Advisory
http://secunia.com/advisories/28195 Vendor Advisory
http://secunia.com/advisories/28266 Vendor Advisory
http://secunia.com/advisories/28346 Vendor Advisory
http://secunia.com/advisories/28400 Vendor Advisory
http://secunia.com/advisories/28636 Vendor Advisory
http://secunia.com/advisories/28776 Vendor Advisory
http://secunia.com/advisories/29381 Vendor Advisory
http://secunia.com/advisories/32274 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200712-15.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-26-234701-1
http://www.debian.org/security/2008/dsa-1487
http://www.mandriva.com/security/advisories?name=MDVSA-2008:005
http://www.novell.com/linux/security/advisories/suse_security_summary_report.html
http://www.redhat.com/support/errata/RHSA-2007-1165.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2007-1166.html Vendor Advisory
http://www.securityfocus.com/archive/1/485822/100/0/threaded
http://www.securityfocus.com/bid/26942
http://www.securitytracker.com/id?1019124
http://www.ubuntu.com/usn/usn-654-1
http://www.vupen.com/english/advisories/2007/4278 Vendor Advisory
http://www.vupen.com/english/advisories/2008/0947/references Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=425561
https://bugzilla.redhat.com/show_bug.cgi?id=425621
https://bugzilla.redhat.com/show_bug.cgi?id=425631
https://exchange.xforce.ibmcloud.com/vulnerabilities/39167
https://issues.rpath.com/browse/RPL-2068
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11029
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4814
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00597.html
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00626.html
http://bugs.gentoo.org/show_bug.cgi?id=202350
http://osvdb.org/42653
http://secunia.com/advisories/28076 Vendor Advisory
http://secunia.com/advisories/28127 Vendor Advisory
http://secunia.com/advisories/28195 Vendor Advisory
http://secunia.com/advisories/28266 Vendor Advisory

Track CVE-2007-6352 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2007-6352), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.