CVE-2018-11037: Infoleak
Published May 14, 2018
·Updated
A flaw was found in Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a crafted file.
References: https://github.com/Exiv2/exiv2/issues/307
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
May 14, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
May 17, 2018
Data Sourced
via Red Hat·09:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-11037?
CVE-2018-11037 is classified as a medium severity vulnerability.
2
How do I fix CVE-2018-11037?
To fix CVE-2018-11037, upgrade Exiv2 to version 0.27 or later.
3
What type of vulnerability is CVE-2018-11037?
CVE-2018-11037 is an information leak vulnerability.
4
Which software is affected by CVE-2018-11037?
CVE-2018-11037 affects Exiv2 version 0.26.
5
Can CVE-2018-11037 be exploited remotely?
Yes, CVE-2018-11037 can be exploited by remote attackers using crafted files.