First published: Wed Feb 20 2019(Updated: )
An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust available CPU resources.
Credit: PSIRT-CNA@flexerasoftware.com PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libexif Project Libexif | =0.6.21 | |
debian/libexif | 0.6.22-3 0.6.24-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-20030.
The severity of CVE-2018-20030 is high with a CVSS score of 7.5.
The vulnerability CVE-2018-20030 can be exploited to exhaust available CPU resources.
The affected software versions include libexif version 0.6.21-4ubuntu0.2, 0.6.21-1ubuntu1+, 0.6.21-2ubuntu0.2, 0.6.21-5.1+deb10u5, 0.6.22-3, and 0.6.24-1.
The remedy for CVE-2018-20030 is to update libexif to version 0.6.21-4ubuntu0.2, 0.6.21-1ubuntu1+, 0.6.21-2ubuntu0.2, 0.6.21-5.1+deb10u5, 0.6.22-3, or 0.6.24-1.