CVE-2017-12956: Medium severity exiv2 exiv2 vulnerability
Published Aug 18, 2017
·Updated
There is an illegal address access in Exiv2::FileIo::pathabi:cxx11 in basicio.cpp of libexiv2 in Exiv2 0.26 that will lead to remote denial of service.
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Aug 18, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12956?
CVE-2017-12956 has a high severity rating due to its potential to cause remote denial of service.
2
How does CVE-2017-12956 affect Exiv2 version 0.26?
CVE-2017-12956 allows for illegal address access in Exiv2 version 0.26, which can lead to a crash or denial of service.
3
How do I fix CVE-2017-12956?
To fix CVE-2017-12956, promptly update to a patched version of Exiv2 that addresses this vulnerability.
4
What software is affected by CVE-2017-12956?
CVE-2017-12956 specifically affects Exiv2 version 0.26 of the libexiv2 library.
5
Can CVE-2017-12956 be exploited remotely?
Yes, CVE-2017-12956 can be exploited remotely, making it a critical vulnerability for systems running the affected software.