CVE-2017-17723: High severity exiv2 exiv2 vulnerability
Published Feb 12, 2018
·Updated
In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp. Remote attackers can exploit this vulnerability to disclose memory data or cause a denial of service via a crafted TIFF file.
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Feb 12, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17723?
CVE-2017-17723 has a medium severity rating due to its potential to disclose memory data or cause denial of service.
2
How do I fix CVE-2017-17723?
To fix CVE-2017-17723, upgrade to a version of Exiv2 that is higher than 0.26 where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2017-17723?
CVE-2017-17723 is classified as a heap-based buffer over-read vulnerability.
4
What software is affected by CVE-2017-17723?
CVE-2017-17723 affects Exiv2 version 0.26 specifically.
5
Can CVE-2017-17723 be exploited remotely?
Yes, CVE-2017-17723 can be exploited remotely via a crafted TIFF file.