CVE-2017-14859: Buffer Overflow
An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14859?
CVE-2017-14859 is classified as a denial of service vulnerability due to an invalid memory address dereference causing application crashes.
How do I fix CVE-2017-14859?
To fix CVE-2017-14859, upgrade the Exiv2 package to versions 0.25-3.1ubuntu0.18.04.2, 0.25-4ubuntu0.1, 0.23-1ubuntu2.2, or newer.
What software is affected by CVE-2017-14859?
CVE-2017-14859 affects Exiv2 version 0.26 and earlier versions in Ubuntu and Debian systems.
Can CVE-2017-14859 be exploited remotely?
Yes, CVE-2017-14859 could potentially be exploited remotely, leading to denial of service.
Is there a workaround for CVE-2017-14859?
Currently, the best approach for CVE-2017-14859 is to update the software rather than rely on a workaround.