PT-2019-6193 · Exiv2+1 · Exiv2+1

92Wyunchao

·

Publicado

2019-08-23

·

Atualizado

2023-12-22

·

CVE-2020-18773

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Exiv2 version 0.27.99.0
Description The issue is related to an invalid memory access in the decode function of the iptc.cpp component in the Exiv2 library, which can lead to a buffer overflow. This allows a remote attacker to cause a denial of service (DOS) by using a specially crafted tif file.
Recommendations For Exiv2 version 0.27.99.0, consider disabling the decode function in iptc.cpp as a temporary workaround to prevent exploitation until a patch is available. Restrict access to the iptc.cpp component to minimize the risk of denial of service attacks. Avoid using the affected Exiv2 library with untrusted tif files until the issue is resolved.

Exploit

Correção

DoS

Buffer Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02063
CVE-2020-18773

Produtos afetados

Debian
Exiv2