PT-2018-13957 · Exiv2+6 · Exiv2+6

Marsman1996

·

Published

2018-09-17

·

Updated

2024-06-15

·

CVE-2018-17230

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 version 0.26
Description The issue allows remote attackers to cause a denial of service, specifically a heap-based buffer overflow, via a crafted image file. This is due to a problem in the Exiv2::ul2Data function in types.cpp.
Recommendations For Exiv2 version 0.26, update to a version that fixes this issue to prevent potential denial of service attacks.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:1577
ALT-PU-2019-2468
ALT-PU-2019-2590
CESA-2020_1577
CVE-2018-17230
OPENSUSE-SU-2020:0482-1
OPENSUSE-SU-2020_0482-1
OPENSUSE-SU-2024:12399-1
RHSA-2020:1577
RHSA-2020_1577
RLSA-2020:1577
SUSE-SU-2020:0921-1

Affected Products

Alt Linux
Almalinux
Centos
Exiv2
Red Hat
Rocky Linux
Suse