CVE-2017-1000127: Buffer Overflow
Published Nov 17, 2017
·Updated
Exiv2 0.26 contains a heap buffer overflow in tiff parser
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Nov 17, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000127?
CVE-2017-1000127 is considered to have a high severity due to the potential for exploitation through a heap buffer overflow.
2
How do I fix CVE-2017-1000127?
To fix CVE-2017-1000127, upgrade Exiv2 to version 0.27 or later, as this version addresses the vulnerability.
3
What software is affected by CVE-2017-1000127?
CVE-2017-1000127 specifically affects Exiv2 version 0.26.
4
What happens if I don't address CVE-2017-1000127?
If CVE-2017-1000127 is not addressed, an attacker may exploit the heap buffer overflow to execute arbitrary code.
5
Is CVE-2017-1000127 related to image processing?
Yes, CVE-2017-1000127 is related to image processing, as it involves a vulnerability in the TIFF parser used by Exiv2.