PT-2008-4141 · Exiv2 · Exiv2

Joakim Bildrulle

·

Published

2008-06-13

·

Updated

2017-08-08

·

CVE-2008-2696

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Exiv2 version 0.16
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash, by exploiting a divide-by-zero error. This is achieved by inserting a zero value in Nikon lens information within the metadata of an image. The error is related to the "pretty printing" functionality and the RationalValue::toLong function.
Recommendations For Exiv2 version 0.16, consider disabling the "pretty printing" feature or restricting access to metadata editing until a patch is available. Avoid using the RationalValue::toLong function with untrusted image metadata to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2696

Affected Products

Exiv2