CVE-2017-1000128: Medium severity exiv2 exiv2 vulnerability
Published Nov 17, 2017
·Updated
Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Nov 17, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000128?
CVE-2017-1000128 has a medium severity rating due to the potential for stack out of bounds read vulnerabilities.
2
How do I fix CVE-2017-1000128?
To mitigate CVE-2017-1000128, update to Exiv2 version 0.26 or later which addresses the vulnerability.
3
What types of systems are affected by CVE-2017-1000128?
CVE-2017-1000128 affects systems running Exiv2 version 0.26, specifically when parsing JPEG2000 files.
4
What is Exiv2 and its relation to CVE-2017-1000128?
Exiv2 is a C++ library and command line utility that allows users to manage image metadata, and CVE-2017-1000128 identifies a vulnerability in its JPEG2000 parser.
5
Can CVE-2017-1000128 lead to arbitrary code execution?
CVE-2017-1000128 does not directly lead to arbitrary code execution, but it can expose sensitive information through stack memory.