CVE-2009-3895PoC(libexif_project / libexif)

LOWCVSS 6.8 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for libexif_project libexif systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via an invalid EXIF image. NOTE: some of these details are obtained from third party information.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libexif

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
libexif

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-22: 1PoC Mentioned / Linked · 2026-03-22: 1Exploit Tool / Code · 2026-03-22: 103-22
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • lanadelreyslefthood@mooofinnn
    PoC

    also check out AFL++ in action - with two walkthrough fuzzing cases breaking real bugs (CVE-2019-13288, CVE-2009-3895), with step-by-step walkthroughs and plenty of visuals so you don’t get stuck https://github.com/mooofin/AFL-exercises

    Post summary

    The post showcases AFL++ fuzzing exercises that serve as proof‑of‑concept demonstrations for CVE‑2019‑13288 and CVE‑2009‑3895, providing step‑by‑step walkthroughs and visual aids via a GitHub repository.

    010120189
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibexif_projectlibexif0.6.18--

Explore more