CVE-2018-17229: Buffer Overflow
Published Sep 19, 2018
·Updated
A flaw was found in Exiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
References: https://github.com/Exiv2/exiv2/issues/453
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Sep 19, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Sep 24, 2018
Data Sourced
via Red Hat·09:23 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-17229?
CVE-2018-17229 has a severity level classified as high due to the potential for a denial of service condition.
2
How do I fix CVE-2018-17229?
To fix CVE-2018-17229, upgrade Exiv2 to version 0.27 or later.
3
What type of vulnerability is CVE-2018-17229?
CVE-2018-17229 is a heap-based buffer overflow vulnerability.
4
Who is affected by CVE-2018-17229?
CVE-2018-17229 affects users of Exiv2 version 0.26.
5
What can be exploited in CVE-2018-17229?
CVE-2018-17229 can be exploited by remote attackers using a crafted image file to induce a denial of service.