CVE-2018-18915: Medium severity centos dos2unix vulnerability
A flaw was found in Exiv2 0.27-RC1. An infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp. A crafted input will lead to a remote denial of service attack.
References: https://github.com/Exiv2/exiv2/issues/511
Upstream Patch: https://github.com/Exiv2/exiv2/pull/517
Other sources
There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18915?
CVE-2018-18915 is classified as a denial of service vulnerability due to an infinite loop.
How do I fix CVE-2018-18915?
To fix CVE-2018-18915, upgrade Exiv2 to a version later than 0.27-RC1 that addresses this issue.
What types of attacks can CVE-2018-18915 facilitate?
CVE-2018-18915 facilitates remote denial of service attacks through crafted input.
Which software versions are affected by CVE-2018-18915?
CVE-2018-18915 affects Exiv2 version 0.27-RC1.
Is user intervention required for CVE-2018-18915 to be exploited?
Yes, exploitation of CVE-2018-18915 requires a crafted input to trigger the infinite loop.