CVE-2012-2845: Curtis Galloway Exif

Medium severity, CVSS 6.4. EPSS: 3.6% chance of exploitation in the next 30 days.

Integer overflow in the jpeg_data_load_data function in jpeg-data.c in libjpeg in exif 0.6.20 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain potentially sensitive information via a crafted JPEG file.

Affected products

Published 2012-07-13. Last modified 2026-06-16.