CVE-2018-10999: Medium severity exiv2 exiv2 vulnerability
Published May 12, 2018
·Updated
An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer over-read.
Affected Software
8 affected componentsFixes available
exiv2 exiv2=0.26
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
debian/exiv2
0.27.3-3+deb11u20.27.3-3+deb11u10.27.6-10.28.5+dfsg-10.28.7+dfsg-2
Event History
May 12, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Data Sourced
via NVD·04:29 AM
DescriptionSeverityWeaknessAffected Software
Aug 13, 2024
Data Sourced
via Launchpad·08:03 AM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·04:00 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:00 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-10999?
CVE-2018-10999 has been classified as a moderate severity vulnerability due to the heap-based buffer over-read in Exiv2.
2
How do I fix CVE-2018-10999?
To fix CVE-2018-10999, upgrade Exiv2 to version 0.27.3-3+deb11u2 or later, or install any of the specified secure versions.
3
What software is affected by CVE-2018-10999?
CVE-2018-10999 affects Exiv2 version 0.26 and potentially prior versions on systems like Debian and Ubuntu.
4
Is there a workaround for CVE-2018-10999?
There is no specific workaround for CVE-2018-10999; the recommended action is to upgrade to a patched version.
5
What types of systems are vulnerable to CVE-2018-10999?
CVE-2018-10999 primarily impacts Debian Linux versions 8.0 and 9.0 and Ubuntu Linux versions 14.04, 16.04, 17.10, and 18.04.