suse · CVE-2007-6353

Quick triage

Priority: high Published: 2021-05-30 12:41:03 UTC Updated: 2026-04-18 20:30:16 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2007-6353 severity important: SUSE including 14 source package names (exiv2-0.27.4-1.2, exiv2-0_26, …), 27 product×package rows across 13 product lines (SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS, SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, … (13 product lines)): Fixed 15, Known Not Affected 12.

Description:

Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.

cvelogic Threat Intelligence