CVE-2017-14861: Integer Overflow
Published Sep 28, 2017
·Updated
There is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function of image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Sep 28, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14861?
CVE-2017-14861 is classified as a denial of service vulnerability that can lead to remote exploitation.
2
How do I fix CVE-2017-14861?
To mitigate CVE-2017-14861, users should upgrade to Exiv2 version 0.26 or later if available.
3
What systems are affected by CVE-2017-14861?
CVE-2017-14861 specifically affects Exiv2 version 0.26.
4
What type of vulnerability is CVE-2017-14861?
CVE-2017-14861 is a stack consumption vulnerability that can result in a denial of service.
5
Can CVE-2017-14861 be exploited remotely?
Yes, CVE-2017-14861 can be exploited remotely using crafted input.