PT-2017-19377 · Exiv2 · Exiv2
Published
2017-12-13
·
Updated
2017-12-13
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Exiv2 version 0.26
Description
A heap-based buffer over-read issue exists in the Exiv2::Internal::PngChunk::keyTXTChunk function, located in pngchunk int.cpp. This can be triggered by a crafted PNG file, potentially leading to a remote denial of service attack.
Recommendations
For Exiv2 version 0.26, consider disabling the use of the Exiv2::Internal::PngChunk::keyTXTChunk function until a patch is available. Restrict access to handling PNG files to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Exiv2