CVE-2018-20030: High severity Libexif Project Libexif vulnerability
Published Feb 20, 2019
·Updated
An error when processing the EXIFIFDINTEROPERABILITY and EXIFIFDEXIF tags within libexif version 0.6.21 can be exploited to exhaust available CPU resources.
Affected Software
2 affected componentsFixes available
Libexif Project Libexif=0.6.21
debian/libexif
0.6.22-30.6.24-10.6.25-1
Remediation
Event History
Feb 20, 2019
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·05:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:58 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·06:57 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·06:58 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID for this issue is CVE-2018-20030.
2
What is the severity of CVE-2018-20030?
The severity of CVE-2018-20030 is high with a CVSS score of 7.5.
3
How can the vulnerability CVE-2018-20030 be exploited?
The vulnerability CVE-2018-20030 can be exploited to exhaust available CPU resources.
4
Which software versions are affected by CVE-2018-20030?
The affected software versions include libexif version 0.6.21-4ubuntu0.2, 0.6.21-1ubuntu1+, 0.6.21-2ubuntu0.2, 0.6.21-5.1+deb10u5, 0.6.22-3, and 0.6.24-1.
5
What is the remedy for CVE-2018-20030?
The remedy for CVE-2018-20030 is to update libexif to version 0.6.21-4ubuntu0.2, 0.6.21-1ubuntu1+, 0.6.21-2ubuntu0.2, 0.6.21-5.1+deb10u5, 0.6.22-3, or 0.6.24-1.