CVE-2018-10998: Medium severity exiv2 exiv2 vulnerability
An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
Other sources
An issue was discovered in Exiv2 0.26. The readMetadata function in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
References: https://github.com/Exiv2/exiv2/issues/303
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10998?
CVE-2018-10998 is classified as a denial of service vulnerability.
How do I fix CVE-2018-10998?
To fix CVE-2018-10998, update Exiv2 to version 0.27.3 or higher.
Which versions of Exiv2 are affected by CVE-2018-10998?
Exiv2 versions prior to 0.27.3, including 0.26, are affected by CVE-2018-10998.
Can CVE-2018-10998 be exploited remotely?
Yes, CVE-2018-10998 can be exploited remotely, allowing attackers to trigger a denial of service.
What functions in Exiv2 are involved in CVE-2018-10998?
The vulnerability in CVE-2018-10998 involves the readMetadata function in jp2image.cpp.