CVE-2018-17230: Buffer Overflow
Published Sep 19, 2018
·Updated
A flaw was found in Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
References: https://github.com/Exiv2/exiv2/issues/455
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Sep 19, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Sep 24, 2018
Data Sourced
via Red Hat·09:26 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-17230?
CVE-2018-17230 is classified as a high severity vulnerability due to its potential to cause denial of service through a heap-based buffer overflow.
2
How do I fix CVE-2018-17230?
To fix CVE-2018-17230, upgrade Exiv2 to version 0.27 or later, which includes the necessary patches.
3
What type of vulnerability is CVE-2018-17230?
CVE-2018-17230 is a heap-based buffer overflow vulnerability that can be exploited via a crafted image file.
4
What software versions are affected by CVE-2018-17230?
CVE-2018-17230 specifically affects Exiv2 version 0.26.
5
Is CVE-2018-17230 exploitable remotely?
Yes, CVE-2018-17230 can be exploited by remote attackers using specially crafted image files.