PT-2019-20119 · Exiv2 · Exiv2

Published

2019-10-09

·

Updated

2019-10-09

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 version 0.27.2
Description The issue allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage int.cpp. This is due to the lack of validation of the relationship between the total size and the offset and size.
Recommendations For Exiv2 version 0.27.2, consider applying validation to the relationship between the total size and the offset and size to prevent the crash in Exiv2::getULong. As a temporary workaround, consider implementing input validation in Exiv2::Internal::CiffDirectory::readDirectory to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2019-247

Affected Products

Exiv2