Vulnerability Description
In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write to an unexpected address.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aertherwide | Exiftags | 1.01 |
Related Weaknesses (CWE)
References
- https://blog.yulun.ac.cn/posts/2023/fuzzing-exiftags/ExploitThird Party Advisory
- https://johnst.org/sw/exiftags/Product
- https://blog.yulun.ac.cn/posts/2023/fuzzing-exiftags/ExploitThird Party Advisory
- https://johnst.org/sw/exiftags/Product
FAQ
What is CVE-2023-50671?
CVE-2023-50671 is a vulnerability with a CVSS score of 7.8 (HIGH). In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write to an unexpected address.
How severe is CVE-2023-50671?
CVE-2023-50671 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-50671?
Check the references section above for vendor advisories and patch information. Affected products include: Aertherwide Exiftags.