First published: Tue Nov 27 2018(Updated: )
Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | =0.27-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19607 has a moderate severity level as it can lead to denial of service through a NULL pointer dereference.
To fix CVE-2018-19607, you should upgrade Exiv2 to a version later than 0.27-RC2 that addresses this vulnerability.
CVE-2018-19607 is associated with a denial of service attack caused by processing a specially crafted file.
Exiv2 version 0.27-RC2 is specifically affected by CVE-2018-19607.
CVE-2018-19607 can cause Exiv2 to crash, resulting in a denial of service for users attempting to use the application.