CVE-2017-17724: Medium severity exiv2 exiv2 vulnerability
A flaw was found in Exiv2 0.26. There is a integer underflow, leading to a heap-based buffer over-read, in the Exiv2::IptcData::printStructure function in iptc.cpp. Remote attackers can exploit this vulnerability to cause a denial of service via a crafted TIFF file or, possibly, disclose memory data.
References: https://bugzilla.redhat.com/showbug.cgi?id=1524107 https://github.com/Exiv2/exiv2/issues/210
Other sources
In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::IptcData::printStructure function in iptc.cpp, related to the "!= 0x1c" case. Remote attackers can exploit this vulnerability to cause a denial of service via a crafted TIFF file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17724?
CVE-2017-17724 has a medium severity rating due to its potential to cause denial of service and possible memory data disclosure.
How do I fix CVE-2017-17724?
To fix CVE-2017-17724, update Exiv2 to version 0.26 or later.
What type of attack does CVE-2017-17724 facilitate?
CVE-2017-17724 facilitates a denial of service attack through crafted TIFF files.
Which software versions are affected by CVE-2017-17724?
CVE-2017-17724 affects Exiv2 version 0.26.
Can CVE-2017-17724 lead to data breaches?
Yes, CVE-2017-17724 may potentially disclose sensitive memory data to attackers.