CVE-2017-14864: Buffer Overflow
An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14864?
CVE-2017-14864 has been classified as a denial of service vulnerability due to an invalid memory address dereference.
How do I fix CVE-2017-14864?
To fix CVE-2017-14864, upgrade Exiv2 to versions 0.25-4ubuntu0.1, 0.25-3.1ubuntu0.18.04.2, 0.27.3-3+deb11u2, or other remedial versions depending on your distribution.
Which software is affected by CVE-2017-14864?
CVE-2017-14864 affects Exiv2 version 0.26 and earlier, impacting various Ubuntu and Debian distributions.
What are the symptoms of CVE-2017-14864 exploitation?
Exploitation of CVE-2017-14864 can cause a segmentation fault leading to application crashes.
Is CVE-2017-14864 still a risk if my system is updated?
If your system is updated to the recommended versions, CVE-2017-14864 should no longer pose a risk.