First published: Mon Feb 12 2018(Updated: )
In Exiv2 0.26, there is a reachable assertion in the readHeader function in bigtiffimage.cpp, which will lead to a remote denial of service attack via a crafted TIFF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | =0.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17722 is classified as a critical severity vulnerability due to its potential to cause a remote denial of service.
To fix CVE-2017-17722, upgrade Exiv2 to a version higher than 0.26 that does not contain this vulnerability.
CVE-2017-17722 is caused by a reachable assertion failure in the readHeader function of bigtiffimage.cpp in Exiv2 0.26.
The impact of CVE-2017-17722 on users includes the risk of a remote denial of service attack when processing crafted TIFF files.
Exiv2 version 0.26 is affected by CVE-2017-17722.