First published: Wed Dec 12 2018(Updated: )
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix | =0.27-rc3 | |
Debian | =8.0 | |
Debian | =10.0 | |
Fedora | =30 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20097 is classified as a denial of service vulnerability due to a segmentation fault in Exiv2 0.27-RC3.
To mitigate CVE-2018-20097, upgrade to a patched version of Exiv2 that addresses the segmentation fault.
CVE-2018-20097 specifically affects Exiv2 version 0.27-RC3.
CVE-2018-20097 impacts multiple systems including Debian 8.0, Debian 10.0, Fedora 30, and Red Hat Enterprise Linux 7.0.
CVE-2018-20097 can be exploited to execute a remote denial of service attack through crafted input.