CVE-2018-12264: Integer Overflow
A flaw was found in Exiv2 0.26. An integer overflow in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.hpp.
References: https://github.com/Exiv2/exiv2/issues/366 https://github.com/TeamSeri0us/pocs/blob/master/exiv2/2-out-of-read-Poc
Patch: https://github.com/Exiv2/exiv2/commit/341de4500ab993103c215bfb07d43d4a08654ac4
Other sources
Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.hpp.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12264?
CVE-2018-12264 is considered to have a high severity due to its potential for leading to an out-of-bounds read that can be exploited for denial of service or arbitrary code execution.
How do I fix CVE-2018-12264?
To fix CVE-2018-12264, users should upgrade Exiv2 to version 0.27.3-3+deb11u2 or later.
Which versions of Exiv2 are affected by CVE-2018-12264?
CVE-2018-12264 affects Exiv2 version 0.26 and all prior versions.
What platforms are impacted by CVE-2018-12264?
CVE-2018-12264 impacts platforms running Exiv2 0.26, particularly Debian and Ubuntu distributions.
Is CVE-2018-12264 being actively exploited?
As of now, there are no confirmed reports indicating active exploitation of CVE-2018-12264, but it remains a potential risk.