CVE-2017-11340: Input Validation
Published Jul 16, 2017
·Updated
There is a Segmentation fault in the XmpParser::terminate() function in Exiv2 0.26, related to an exit call. A Crafted input will lead to a remote denial of service attack.
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Jul 16, 2017
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11340?
CVE-2017-11340 has a severity rating of medium, as it can cause a denial of service.
2
How do I fix CVE-2017-11340?
To fix CVE-2017-11340, it is recommended to upgrade Exiv2 to version 0.27 or later.
3
What type of attack does CVE-2017-11340 facilitate?
CVE-2017-11340 facilitates a remote denial of service attack due to a segmentation fault.
4
Which versions of Exiv2 are affected by CVE-2017-11340?
CVE-2017-11340 affects Exiv2 version 0.26.
5
What function in Exiv2 is associated with CVE-2017-11340?
CVE-2017-11340 is associated with the XmpParser::terminate() function.