First published: Fri Nov 17 2017(Updated: )
Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix | =0.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000128 has a medium severity rating due to the potential for stack out of bounds read vulnerabilities.
To mitigate CVE-2017-1000128, update to Exiv2 version 0.26 or later which addresses the vulnerability.
CVE-2017-1000128 affects systems running Exiv2 version 0.26, specifically when parsing JPEG2000 files.
Exiv2 is a C++ library and command line utility that allows users to manage image metadata, and CVE-2017-1000128 identifies a vulnerability in its JPEG2000 parser.
CVE-2017-1000128 does not directly lead to arbitrary code execution, but it can expose sensitive information through stack memory.