CVE-2018-17581: Medium severity exiv2 exiv2 vulnerability
A flaw was found in Exiv2 0.26. The CiffDirectory::readDirectory() function at crwimageint.cpp has an excessive stack consumption due to a recursive function, leading to Denial of service.
References: https://github.com/Exiv2/exiv2/issues/460 https://github.com/SegfaultMasters/covering360/blob/master/Exiv2
Other sources
CiffDirectory::readDirectory() at crwimageint.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17581?
CVE-2018-17581 has been classified as a Denial of Service vulnerability due to excessive stack consumption.
How do I fix CVE-2018-17581?
To fix CVE-2018-17581, update to Exiv2 version 0.27 or later, or the specific patched versions indicated for your distribution.
Which software versions are affected by CVE-2018-17581?
CVE-2018-17581 affects Exiv2 versions prior to 0.27, specifically 0.26 and 0.25 on various distributions.
What operating systems are impacted by CVE-2018-17581?
CVE-2018-17581 impacts various operating systems that use affected versions of Exiv2, including Ubuntu and Debian.
Is CVE-2018-17581 a remote exploit?
CVE-2018-17581 can potentially be exploited remotely as it leads to a Denial of Service condition.