First published: Wed Dec 12 2018(Updated: )
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack. Upstream issue: <a href="https://github.com/Exiv2/exiv2/issues/590">https://github.com/Exiv2/exiv2/issues/590</a> References: <a href="https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206">https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | =0.27-rc3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-20098 is rated as medium with a CVSS score of 6.5.
To fix the vulnerability, it is recommended to update Exiv2 to a version beyond 0.27-RC3.
The CWE associated with CVE-2018-20098 is CWE-125.