PT-2017-19377 · Exiv2 · Exiv2

Published

2017-12-13

·

Updated

2017-12-13

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 version 0.26
Description A heap-based buffer over-read issue exists in the Exiv2::Internal::PngChunk::keyTXTChunk function, located in pngchunk int.cpp. This can be triggered by a crafted PNG file, potentially leading to a remote denial of service attack.
Recommendations For Exiv2 version 0.26, consider disabling the use of the Exiv2::Internal::PngChunk::keyTXTChunk function until a patch is available. Restrict access to handling PNG files to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2017-140

Affected Products

Exiv2