CVE-2018-19607: Null Pointer Dereference
An issue was found in Exiv2 v0.27-RC2. A NULL pointer dereference in Exiv2::isoSpeed in easyaccess.cpp allows remote attackers to cause a denial of service via a crafted file.
References: https://github.com/Exiv2/exiv2/issues/561
Other sources
Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19607?
CVE-2018-19607 has a moderate severity level as it can lead to denial of service through a NULL pointer dereference.
How do I fix CVE-2018-19607?
To fix CVE-2018-19607, you should upgrade Exiv2 to a version later than 0.27-RC2 that addresses this vulnerability.
What type of attack is CVE-2018-19607 associated with?
CVE-2018-19607 is associated with a denial of service attack caused by processing a specially crafted file.
Which versions of Exiv2 are affected by CVE-2018-19607?
Exiv2 version 0.27-RC2 is specifically affected by CVE-2018-19607.
How does CVE-2018-19607 impact Exiv2?
CVE-2018-19607 can cause Exiv2 to crash, resulting in a denial of service for users attempting to use the application.