CVE-2017-17669: Medium severity exiv2 exiv2 vulnerability
Published Dec 13, 2017
·Updated
Last updated 25 August 2025
Other sources
There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunkint.cpp in Exiv2 0.26. A crafted PNG file will lead to a remote denial of service attack.
— Launchpad
Affected Software
7 affected componentsFixes available
exiv2 exiv2=0.26
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Debian Debian Linux=10.0
debian/exiv2
0.27.3-3+deb11u20.27.3-3+deb11u10.27.6-10.28.5+dfsg-10.28.7+dfsg-2
Remediation
Event History
Dec 13, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:29 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:34 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:19 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:20 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-17669?
CVE-2017-17669 has a severity rating that suggests it can lead to a remote denial of service attack.
2
How do I fix CVE-2017-17669?
To fix CVE-2017-17669, upgrade Exiv2 to versions 0.25-3.1ubuntu0.18.04.2 or higher for Ubuntu, or appropriate patched versions in Debian.
3
What are the affected software versions for CVE-2017-17669?
CVE-2017-17669 affects Exiv2 versions up to and including 0.26.
4
Can CVE-2017-17669 be exploited remotely?
Yes, CVE-2017-17669 can be exploited remotely through specially crafted PNG files.
5
Is there a workaround for CVE-2017-17669 if I can't upgrade?
There are no specific workarounds provided for CVE-2017-17669; the best solution is to apply the necessary software updates.