CVE-2017-9953: Use After Free
Published Jun 26, 2017
·Updated
There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.
Affected Software
2 affected components
exiv2 exiv2=0.26
redhat Enterprise Linux=7.0
Event History
Jun 26, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9953?
CVE-2017-9953 is classified as a denial of service vulnerability that can lead to a segmentation fault in Exiv2 0.26.
2
How do I fix CVE-2017-9953?
To fix CVE-2017-9953, upgrade Exiv2 to a version newer than 0.26 where the vulnerability is patched.
3
What software is affected by CVE-2017-9953?
CVE-2017-9953 affects Exiv2 version 0.26 and Red Hat Enterprise Linux 7.0.
4
Can CVE-2017-9953 be exploited remotely?
Yes, CVE-2017-9953 can be exploited remotely through crafted input, leading to denial of service.
5
What happens if I am affected by CVE-2017-9953?
If you are affected by CVE-2017-9953, you may experience application crashes and service interruptions.