CVE-2017-11591: High severity exiv2 exiv2 vulnerability
Published Jul 24, 2017
·Updated
Last updated 25 August 2025
Other sources
There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
— Launchpad
Affected Software
7 affected componentsFixes available
exiv2 exiv2=0.26
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Debian Debian Linux=10.0
debian/exiv2
0.27.3-3+deb11u20.27.3-3+deb11u10.27.6-10.28.5+dfsg-10.28.7+dfsg-2
Remediation
Event History
Jul 24, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:29 AM
DescriptionSeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:26 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:19 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:20 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-11591?
CVE-2017-11591 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2017-11591?
To fix CVE-2017-11591, update to a version of Exiv2 that is newer than 0.26.
3
What are the affected versions of Exiv2 in CVE-2017-11591?
The affected version of Exiv2 in CVE-2017-11591 is 0.26.
4
Can CVE-2017-11591 be exploited remotely?
Yes, CVE-2017-11591 can be exploited remotely through crafted input.
5
Which operating systems are impacted by CVE-2017-11591?
CVE-2017-11591 impacts Ubuntu and Debian systems using the vulnerable version of Exiv2.