CVE-2018-10772: Buffer Overflow
Exiv2 through version 0.26 is vulnerable to a segmentation fault in the pngimage.cpp:tEXtToDataBuf() function. An attacker could exploit this to cause a denial of service or via crafted file.
Product Bug:
https://bugzilla.redhat.com/showbug.cgi?id=1566260
Other sources
The tEXtToDataBuf function in pngimage.cpp in Exiv2 through 0.26 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10772?
CVE-2018-10772 is classified with a medium severity level due to its potential to cause application crashes.
How do I fix CVE-2018-10772?
To fix CVE-2018-10772, upgrade Exiv2 to version 0.27 or later.
What type of vulnerability is CVE-2018-10772?
CVE-2018-10772 is a denial of service vulnerability caused by a segmentation fault in the tEXtToDataBuf function.
Which software versions are affected by CVE-2018-10772?
Exiv2 versions up to and including 0.26 are affected by CVE-2018-10772.
How can CVE-2018-10772 be exploited?
CVE-2018-10772 can be exploited by remote attackers using crafted PNG files to trigger application crashes.