PT-2019-20120 · Exiv2 · Exiv2

Published

2019-02-25

·

Updated

2019-02-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 version 0.27
Description An issue in Exiv2 allows an attacker to cause Denial of Service or possibly have other unspecified impact by triggering infinite recursion with a crafted file. This recursion occurs at Exiv2::Image::printTiffStructure in the file image.cpp.
Recommendations For Exiv2 version 0.27, consider avoiding the use of crafted files that may trigger the infinite recursion at Exiv2::Image::printTiffStructure until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2019-248

Affected Products

Exiv2