CVE-2005-0406

A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.
Configurations

Configuration 1 (hide)

cpe:2.3:a:image_processing_project:image_processing:-:*:*:*:*:*:*:*

History

20 Nov 2024, 23:55

Type Values Removed Values Added
References () http://seclists.org/lists/fulldisclosure/2005/Feb/0343.html - Mailing List, Third Party Advisory () http://seclists.org/lists/fulldisclosure/2005/Feb/0343.html - Mailing List, Third Party Advisory
References () http://www.redteam-pentesting.de/advisories/rt-sa-2005-008.txt - Exploit, Vendor Advisory () http://www.redteam-pentesting.de/advisories/rt-sa-2005-008.txt - Exploit, Vendor Advisory

15 Feb 2024, 20:19

Type Values Removed Values Added
CVSS v2 : 2.1
v3 : unknown
v2 : 2.1
v3 : 5.5
CPE cpe:2.3:a:image_processing_software:image_processing_software:*:*:*:*:*:*:*:* cpe:2.3:a:image_processing_project:image_processing:-:*:*:*:*:*:*:*
CWE NVD-CWE-Other CWE-212
References (FULLDISC) http://seclists.org/lists/fulldisclosure/2005/Feb/0343.html - (FULLDISC) http://seclists.org/lists/fulldisclosure/2005/Feb/0343.html - Mailing List, Third Party Advisory
First Time Image Processing Project
Image Processing Project image Processing

Information

Published : 2005-02-14 05:00

Updated : 2024-11-20 23:55


NVD link : CVE-2005-0406

Mitre link : CVE-2005-0406

CVE.ORG link : CVE-2005-0406


JSON object : View

Products Affected

image_processing_project

  • image_processing
CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer