CVE-2017-14862: Buffer Overflow
Published Sep 29, 2017
·Updated
An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
Affected Software
7 affected componentsFixes available
exiv2 exiv2=0.26
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Debian Debian Linux=10.0
debian/exiv2
0.27.3-3+deb11u20.27.3-3+deb11u10.27.6-10.28.5+dfsg-10.28.7+dfsg-2
Event History
Sep 28, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 29, 2017
Data Sourced
via NVD·01:34 AM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:30 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:19 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:20 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-14862?
CVE-2017-14862 has a severity level that could lead to denial of service due to application crashes.
2
How do I fix CVE-2017-14862?
To fix CVE-2017-14862, update Exiv2 to versions 0.25-4ubuntu0.1 or later on Ubuntu, 0.27.3-3+deb11u2 or later on Debian.
3
What software is affected by CVE-2017-14862?
CVE-2017-14862 affects Exiv2 version 0.26 and earlier versions on specific Ubuntu and Debian distributions.
4
What type of vulnerability is CVE-2017-14862?
CVE-2017-14862 is classified as an Invalid memory address dereference vulnerability.
5
Can CVE-2017-14862 be exploited remotely?
CVE-2017-14862 can potentially be exploited remotely to cause a denial of service.