CVE-2018-14046: High severity centos dos2unix vulnerability
A flaw was found in Exiv2 0.26. A heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.
References: https://github.com/Exiv2/exiv2/issues/378
Upstream patch: https://github.com/Exiv2/exiv2/commit/505e2417e408abaf8f9fe9e5076f567a65cc59c3
Other sources
Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14046?
CVE-2018-14046 is considered to be of medium severity due to its potential for causing a heap-based buffer over-read.
How do I fix CVE-2018-14046?
To fix CVE-2018-14046, upgrade Exiv2 to version 0.27 or later, where the vulnerability has been addressed.
Which versions of Exiv2 are affected by CVE-2018-14046?
CVE-2018-14046 affects Exiv2 version 0.26 specifically.
What type of vulnerability is CVE-2018-14046?
CVE-2018-14046 is a heap-based buffer over-read vulnerability found in the WebPImage::decodeChunks function.
Can CVE-2018-14046 lead to further security issues?
Yes, CVE-2018-14046 could potentially lead to information disclosure or other unexpected behaviors in the application.