First published: Mon Jun 26 2017(Updated: )
There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | =0.26 | |
Red Hat Enterprise Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9953 is classified as a denial of service vulnerability that can lead to a segmentation fault in Exiv2 0.26.
To fix CVE-2017-9953, upgrade Exiv2 to a version newer than 0.26 where the vulnerability is patched.
CVE-2017-9953 affects Exiv2 version 0.26 and Red Hat Enterprise Linux 7.0.
Yes, CVE-2017-9953 can be exploited remotely through crafted input, leading to denial of service.
If you are affected by CVE-2017-9953, you may experience application crashes and service interruptions.