CVE-2018-10958: Buffer Overflow
Published May 10, 2018
·Updated
In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call.
Affected Software
8 affected componentsFixes available
exiv2 exiv2=0.26
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
debian/exiv2
0.27.3-3+deb11u20.27.3-3+deb11u10.27.6-10.28.5+dfsg-10.28.7+dfsg-2
Event History
May 10, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·02:29 AM
DescriptionSeverityWeaknessAffected Software
May 16, 2018
Data Sourced
via Red Hat·06:13 AM
DescriptionSeverityAffected Software
Aug 13, 2024
Data Sourced
via Launchpad·08:03 AM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·04:00 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:00 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-10958?
CVE-2018-10958 has a medium severity due to its potential to cause application crashes.
2
How do I fix CVE-2018-10958?
To fix CVE-2018-10958, upgrade Exiv2 to version 0.27.3-3+deb11u2 or later.
3
Which versions of Exiv2 are affected by CVE-2018-10958?
Exiv2 version 0.26 is the only version directly affected by CVE-2018-10958.
4
What software is impacted by CVE-2018-10958?
CVE-2018-10958 impacts Exiv2 0.26, particularly on Debian and Ubuntu systems.
5
Can CVE-2018-10958 lead to denial of service?
Yes, CVE-2018-10958 can lead to denial of service through application crashes during memory allocation.