CVE-2017-11592: Buffer Overflow
Published Jul 24, 2017
·Updated
There is a Mismatched Memory Management Routines vulnerability in the Exiv2::FileIo::seek function of Exiv2 0.26 that will lead to a remote denial of service attack (heap memory corruption) via crafted input.
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Jul 24, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11592?
The severity of CVE-2017-11592 is classified as important due to the potential for remote denial of service attacks.
2
How do I fix CVE-2017-11592?
To fix CVE-2017-11592, upgrade Exiv2 to version 0.27 or later, as the vulnerability has been addressed in those releases.
3
What type of attack is possible with CVE-2017-11592?
CVE-2017-11592 allows for a remote denial of service attack caused by heap memory corruption.
4
Which version of Exiv2 is affected by CVE-2017-11592?
Only Exiv2 version 0.26 is affected by CVE-2017-11592.
5
What functions are related to the vulnerability in CVE-2017-11592?
The vulnerability in CVE-2017-11592 is related to the Exiv2::FileIo::seek function.