CVE-2017-11553: Input Validation
Published Jul 23, 2017
·Updated
There is an illegal address access in the extendaliastable function in localealias.c of Exiv2 0.26. A crafted input will lead to remote denial of service.
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Jul 23, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11553?
CVE-2017-11553 has been classified as a high-severity vulnerability due to the potential for remote denial of service.
2
How do I fix CVE-2017-11553?
To fix CVE-2017-11553, upgrade Exiv2 to the latest version that addresses this vulnerability.
3
What software versions are affected by CVE-2017-11553?
CVE-2017-11553 affects Exiv2 version 0.26.
4
What kind of attack does CVE-2017-11553 enable?
CVE-2017-11553 enables an attacker to execute a remote denial of service attack.
5
Is there a workaround for CVE-2017-11553?
There are no known effective workarounds for CVE-2017-11553 other than updating to a secure version.