PT-2018-10098 · Exiv2+6 · Exiv2+6

C1208828

·

Published

2018-04-12

·

Updated

2022-10-17

·

CVE-2018-10772

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 versions prior to 0.27
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash, or possibly have other unspecified impacts through a crafted file. This is due to the tEXtToDataBuf function in pngimage.cpp.
Recommendations For Exiv2 versions prior to 0.27, update to version 0.27 or later to resolve the issue.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2020:1577
ALT-PU-2019-2468
ALT-PU-2019-2590
CESA-2019_2101
CESA-2020_1577
CVE-2018-10772
OPENSUSE-SU-2022_3598-1
RHSA-2019:2101
RHSA-2019_2101
RHSA-2020:1577
RHSA-2020_1577
RLSA-2020:1577
SUSE-SU-2022:3598-1
SUSE-SU-2022_3598-1

Affected Products

Alt Linux
Almalinux
Centos
Exiv2
Red Hat
Rocky Linux
Suse