PT-2018-2292 · Exiv2+3 · Exiv2+3

Fgeeko

·

Published

2018-04-22

·

Updated

2022-11-29

·

CVE-2018-11531

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 version 0.26
Description The issue is related to a heap-based buffer overflow in the getData function, located in preview.cpp, which can be exploited by a remote attacker using a specially crafted malicious file. This could potentially lead to a denial of service or allow the execution of arbitrary code.
Recommendations For Exiv2 version 0.26, consider disabling the getData function in preview.cpp as a temporary workaround until a patch is available. Restrict the use of Exiv2 to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2105
ALT-PU-2019-2468
ALT-PU-2019-2590
BDU:2019-00418
CVE-2018-11531
DLA-1402-1
DSA-4238-1
OPENSUSE-SU-2022_4208-1
OPENSUSE-SU-2022_4276-1
SUSE-SU-2018:3882-1
SUSE-SU-2018:3882-2
SUSE-SU-2022:4208-1
SUSE-SU-2022:4276-1
USN-3700-1

Affected Products

Alt Linux
Exiv2
Suse
Ubuntu