CVE-2012-2845: Curtis Galloway Exif
Medium severity, CVSS 6.4. EPSS: 3.6% chance of exploitation in the next 30 days.
Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.
Affected products
- Curtis Galloway Exif: version 0.6.20 only
Published 2012-07-13. Last modified 2026-06-16.