CVE-2008-2696: Medium severity centos dos2unix vulnerability
Published Jun 13, 2008
·Updated
Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong function.
Affected Software
1 affected component
exiv2 exiv2=0.16
Event History
Jun 13, 2008
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2696?
CVE-2008-2696 has a high severity rating due to its potential to cause application crashes.
2
How does CVE-2008-2696 impact users?
CVE-2008-2696 allows remote attackers to cause a denial of service, resulting in application crashes under specific conditions.
3
What versions of Exiv2 are affected by CVE-2008-2696?
CVE-2008-2696 specifically affects Exiv2 version 0.16.
4
How do I fix CVE-2008-2696?
To fix CVE-2008-2696, users should upgrade Exiv2 to a version that resolves this vulnerability.
5
What specific functionality in Exiv2 is related to CVE-2008-2696?
CVE-2008-2696 is related to errors in handling Nikon lens information during the 'pretty printing' process.