CVE-2018-11531: Buffer Overflow
Published May 29, 2018
·Updated
Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.
Affected Software
8 affected componentsFixes available
exiv2 exiv2=0.26
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
debian/exiv2
0.27.3-3+deb11u20.27.3-3+deb11u10.27.6-10.28.5+dfsg-10.28.7+dfsg-2
Event History
May 29, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Data Sourced
via NVD·07:29 AM
DescriptionSeverityWeaknessAffected Software
Aug 9, 2024
Data Sourced
via Launchpad·08:02 AM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·04:00 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:00 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-11531?
CVE-2018-11531 has a high severity rating due to the heap-based buffer overflow vulnerability it introduces.
2
How do I fix CVE-2018-11531?
To fix CVE-2018-11531, upgrade to versions 0.27.3-3+deb11u2, 0.27.3-3+deb11u1, 0.27.6-1, or 0.28.3+dfsg-2 of Exiv2.
3
Which software is affected by CVE-2018-11531?
CVE-2018-11531 specifically affects Exiv2 version 0.26.
4
What type of vulnerability is CVE-2018-11531?
CVE-2018-11531 is classified as a heap-based buffer overflow vulnerability.
5
On which platforms can CVE-2018-11531 be found?
CVE-2018-11531 can be found on Debian Linux 8.0, 9.0, and various versions of Ubuntu Linux including 14.04, 16.04, 17.10, and 18.04.