PT-2008-4141 · Exiv2 · Exiv2

Joakim Bildrulle

·

Publicado

2008-06-13

·

Atualizado

2017-08-08

·

CVE-2008-2696

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Exiv2 version 0.16
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash, by exploiting a divide-by-zero error. This is achieved by inserting a zero value in Nikon lens information within the metadata of an image. The error is related to the "pretty printing" functionality and the RationalValue::toLong function.
Recommendations For Exiv2 version 0.16, consider disabling the "pretty printing" feature or restricting access to metadata editing until a patch is available. Avoid using the RationalValue::toLong function with untrusted image metadata to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2696

Produtos afetados

Exiv2