PT-2017-18798 · Exiv2+3 · Exiv2+3

Ch Rover

·

Publicado

2017-05-26

·

Atualizado

2024-06-15

·

CVE-2017-9239

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 version 0.26
Description An issue in the handling of the ifd structure can lead to a segmentation fault when a crafted tiff file is opened, potentially causing the program to crash. The issue arises when the data structure of the ifd is incorrect, resulting in the assignment of pValue to 0x0, and subsequently, the value of pValue() is 0x0. This value is then used by TiffImageEntry::doWriteImage, leading to the segmentation fault.
Recommendations For Exiv2 version 0.26, consider avoiding the use of crafted tiff files until a patch is available. As a temporary workaround, restrict the opening of tiff files from untrusted sources to minimize the risk of exploitation.

Exploit

Correção

Divide By Zero

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2468
ALT-PU-2019-2590
CVE-2017-9239
DLA-963-1
OPENSUSE-SU-2020:0482-1
OPENSUSE-SU-2020_0482-1
OPENSUSE-SU-2024:12399-1
PYSEC-2017-112
SUSE-SU-2020:0860-1
SUSE-SU-2020:0921-1
SUSE-SU-2020_0860-1
USN-3852-1

Produtos afetados

Alt Linux
Exiv2
Suse
Ubuntu