First published: Mon May 14 2018(Updated: )
A flaw was found in Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a crafted file. References: <a href="https://github.com/Exiv2/exiv2/issues/307">https://github.com/Exiv2/exiv2/issues/307</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | =0.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11037 is classified as a medium severity vulnerability.
To fix CVE-2018-11037, upgrade Exiv2 to version 0.27 or later.
CVE-2018-11037 is an information leak vulnerability.
CVE-2018-11037 affects Exiv2 version 0.26.
Yes, CVE-2018-11037 can be exploited by remote attackers using crafted files.