CVE-2018-12265: Integer Overflow
Published Jun 13, 2018
·Updated
Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.
Affected Software
8 affected componentsFixes available
exiv2 exiv2=0.26
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
debian/exiv2
0.27.3-3+deb11u20.27.3-3+deb11u10.27.6-10.28.5+dfsg-10.28.7+dfsg-2
Remediation
Event History
Jun 13, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Data Sourced
via NVD·11:29 AM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·09:20 PM
DescriptionSeverityAffected Software
Aug 9, 2024
Data Sourced
via Launchpad·08:02 AM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·04:00 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:00 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-12265?
CVE-2018-12265 has a medium severity rating due to its potential to lead to out-of-bounds read vulnerabilities.
2
How do I fix CVE-2018-12265?
To fix CVE-2018-12265, upgrade Exiv2 to version 0.27.3 or later.
3
What software is affected by CVE-2018-12265?
CVE-2018-12265 affects Exiv2 version 0.26 and earlier on Debian and various versions of Ubuntu.
4
What are the consequences of exploiting CVE-2018-12265?
Exploitation of CVE-2018-12265 could lead to application crashes or potentially allow attackers to read sensitive information.
5
Is CVE-2018-12265 present in any major Linux distributions?
Yes, CVE-2018-12265 is present in major Linux distributions such as Debian and Ubuntu, especially in Exiv2 version 0.26.