CVE-2017-18215: Critical severity xv project vulnerability
Published Mar 5, 2018
·Updated
xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, leading to crashes or potentially code execution, because it uses an incorrect length value.
Affected Software
2 affected components
Xv Project Xv=3.10a
openSUSE Leap=42.3
Event History
Mar 5, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18215?
CVE-2017-18215 is classified as a high severity vulnerability due to the potential for memory corruption and code execution.
2
How do I fix CVE-2017-18215?
To fix CVE-2017-18215, update to a patched version of xv, specifically versions that address the memory corruption issue.
3
What software is affected by CVE-2017-18215?
CVE-2017-18215 affects xv version 3.10a and openSUSE Leap 42.3.
4
What type of vulnerability is CVE-2017-18215?
CVE-2017-18215 is a memory corruption vulnerability caused by an out-of-bounds write when decoding PNG comment fields.
5
What are the potential consequences of CVE-2017-18215?
The potential consequences of CVE-2017-18215 include application crashes and the possibility of arbitrary code execution.