CVE-2018-16336: Medium severity exiv2 exiv2 vulnerability
Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE-2018-10999.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability identified by CVE-2018-16336?
CVE-2018-16336 in Exiv2 v0.26 allows remote attackers to cause a denial of service due to a heap-based buffer over-read by using a crafted image file.
What are the affected versions related to CVE-2018-16336?
Exiv2 v0.26 and specific Ubuntu and Debian versions are affected by CVE-2018-16336, including Ubuntu 18.04, 18.10, and various Debian releases.
How do I fix the vulnerability CVE-2018-16336?
To fix CVE-2018-16336, update Exiv2 to a version greater than 0.26, specifically the patched versions provided by your Linux distribution.
What platforms are impacted by CVE-2018-16336?
CVE-2018-16336 impacts various Linux distributions, specifically versions of Exiv2 used in Ubuntu and Debian.
Is CVE-2018-16336 a critical vulnerability?
CVE-2018-16336 is classified as a denial of service vulnerability, which can disrupt service availability but may not necessarily allow for unauthorized access.