PT-2019-5328 · Exiv2+4 · Exiv2+4

Kevinbackhouse

·

Published

2019-06-30

·

Updated

2023-02-02

·

CVE-2019-13110

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Exiv2 versions prior to 0.27.2
Description The issue is caused by an integer overflow and out-of-bounds read in the CiffDirectory::readDirectory function. This allows an attacker to cause a denial of service via a crafted CRW image file. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For Exiv2 versions prior to 0.27.2, update to version 0.27.2 or later to resolve the issue. At the moment, there is no other information about additional mitigation measures for this vulnerability.

Exploit

Fix

DoS

Integer Overflow

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2468
ALT-PU-2019-2590
BDU:2020-02397
CVE-2019-13110
DLA-3265-1
MGASA-2019-0415
OPENSUSE-SU-2022_4208-1
OPENSUSE-SU-2022_4276-1
SUSE-SU-2020:0860-1
SUSE-SU-2022:4208-1
SUSE-SU-2022:4276-1
USN-4056-1

Affected Products

Alt Linux
Astra Linux
Exiv2
Suse
Ubuntu