CVE-2017-11683: Medium severity exiv2 exiv2 vulnerability
Last updated 25 August 2025
Other sources
There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11683?
CVE-2017-11683 has a high severity rating due to its potential for remote denial of service attacks.
How do I fix CVE-2017-11683?
To fix CVE-2017-11683, upgrade to Exiv2 versions 0.27.3-3+deb11u2 or newer, depending on your operating system.
Which versions of Exiv2 are affected by CVE-2017-11683?
Exiv2 version 0.26 is affected by CVE-2017-11683, along with various previous versions listed for Ubuntu and Debian.
Can CVE-2017-11683 be exploited remotely?
Yes, CVE-2017-11683 can be exploited remotely through specially crafted input that triggers the vulnerability.
What type of attack does CVE-2017-11683 enable?
CVE-2017-11683 enables a remote denial of service attack, potentially crashing applications that utilize the Exiv2 library.