First published: Mon Mar 05 2018(Updated: )
xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, leading to crashes or potentially code execution, because it uses an incorrect length value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xv Project | =3.10a | |
SUSE Linux | =42.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18215 is classified as a high severity vulnerability due to the potential for memory corruption and code execution.
To fix CVE-2017-18215, update to a patched version of xv, specifically versions that address the memory corruption issue.
CVE-2017-18215 affects xv version 3.10a and openSUSE Leap 42.3.
CVE-2017-18215 is a memory corruption vulnerability caused by an out-of-bounds write when decoding PNG comment fields.
The potential consequences of CVE-2017-18215 include application crashes and the possibility of arbitrary code execution.