CVE-2017-17722: Medium severity exiv2 exiv2 vulnerability
Published Feb 12, 2018
·Updated
In Exiv2 0.26, there is a reachable assertion in the readHeader function in bigtiffimage.cpp, which will lead to a remote denial of service attack via a crafted TIFF file.
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Feb 12, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17722?
CVE-2017-17722 is classified as a critical severity vulnerability due to its potential to cause a remote denial of service.
2
How do I fix CVE-2017-17722?
To fix CVE-2017-17722, upgrade Exiv2 to a version higher than 0.26 that does not contain this vulnerability.
3
What causes CVE-2017-17722?
CVE-2017-17722 is caused by a reachable assertion failure in the readHeader function of bigtiffimage.cpp in Exiv2 0.26.
4
What impact does CVE-2017-17722 have on users?
The impact of CVE-2017-17722 on users includes the risk of a remote denial of service attack when processing crafted TIFF files.
5
Which versions of Exiv2 are affected by CVE-2017-17722?
Exiv2 version 0.26 is affected by CVE-2017-17722.