First published: Sun Jul 16 2017(Updated: )
There is an invalid free in the Action::TaskFactory::cleanup function of actions.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | =0.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11337 has a CVSS score that indicates a high severity due to the potential for remote denial of service.
To mitigate CVE-2017-11337, update Exiv2 to version 0.26 or apply any available patches.
CVE-2017-11337 exploits an invalid free condition in the cleanup function, allowing crafted input to cause a denial of service.
Yes, CVE-2017-11337 can be exploited remotely due to the nature of the vulnerability affecting a specific function in Exiv2.
CVE-2017-11337 specifically affects Exiv2 version 0.26.