First published: Mon Jul 24 2017(Updated: )
There is a Mismatched Memory Management Routines vulnerability in the Exiv2::FileIo::seek function of Exiv2 0.26 that will lead to a remote denial of service attack (heap memory corruption) via crafted input.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix | =0.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-11592 is classified as important due to the potential for remote denial of service attacks.
To fix CVE-2017-11592, upgrade Exiv2 to version 0.27 or later, as the vulnerability has been addressed in those releases.
CVE-2017-11592 allows for a remote denial of service attack caused by heap memory corruption.
Only Exiv2 version 0.26 is affected by CVE-2017-11592.
The vulnerability in CVE-2017-11592 is related to the Exiv2::FileIo::seek function.