First published: Tue Jul 17 2018(Updated: )
samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple platforms) where glibc is not used, possibly leading to a buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix | =0.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14338 has a high severity level due to the potential for buffer overflow vulnerabilities.
To fix CVE-2018-14338, you should update Exiv2 to a version beyond 0.26 where the vulnerability has been resolved.
The impact of CVE-2018-14338 includes possible exploitation leading to arbitrary code execution via a buffer overflow.
CVE-2018-14338 affects Exiv2 version 0.26 specifically.
Yes, CVE-2018-14338 specifically affects POSIX platforms excluding Apple platforms where glibc is not used.