libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
| Vendor | Product | Versions |
|---|---|---|
| azl3 | libexif | 0.6.24-1 |
Updated vendor to azl3, product to libexif, and marked the vulnerability as actively exploited with an exploit available.
Updated affected versions to include 0.6.24-1, marked exploit as available, marked as actively exploited, and provided a patch available version 0.6.24-2.
Initial creation