CVE-2017-17725: Integer Overflow
In Exiv2 0.26, there is an integer overflow leading to a heap-based buffer over-read in the Exiv2::getULong function in types.cpp. Remote attackers can exploit the vulnerability to cause a denial of service via a crafted image file. Note that this vulnerability is different from CVE-2017-14864, which is an invalid memory address dereference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17725?
The severity of CVE-2017-17725 is classified as a medium risk due to potential denial of service attacks.
How do I fix CVE-2017-17725?
To fix CVE-2017-17725, upgrade Exiv2 to version 0.27 or later, which addresses this vulnerability.
Who is affected by CVE-2017-17725?
CVE-2017-17725 affects users running Exiv2 version 0.26.
What type of attack can CVE-2017-17725 enable?
CVE-2017-17725 can enable remote attackers to perform denial of service attacks via crafted image files.
What is the nature of the vulnerability in CVE-2017-17725?
CVE-2017-17725 is an integer overflow leading to a heap-based buffer over-read in the Exiv2 library.