CVE-2018-5772: Medium severity exiv2 exiv2 vulnerability
Published Jan 18, 2018
·Updated
In Exiv2 0.26, there is a segmentation fault caused by uncontrolled recursion in the Exiv2::Image::printIFDStructure function in the image.cpp file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file.
Affected Software
1 affected component
exiv2 exiv2=0.26
Event History
Jan 18, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Data Sourced
via NVD·07:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5772?
CVE-2018-5772 has a high severity due to the potential for remote denial of service attacks.
2
How do I fix CVE-2018-5772?
The recommended fix for CVE-2018-5772 is to upgrade Exiv2 to a version later than 0.26.
3
What type of attack is associated with CVE-2018-5772?
CVE-2018-5772 is associated with remote denial of service attacks leveraging crafted tif files.
4
Which version of Exiv2 is vulnerable to CVE-2018-5772?
Exiv2 version 0.26 is the only known vulnerable version for CVE-2018-5772.
5
Can CVE-2018-5772 be exploited without user interaction?
Yes, CVE-2018-5772 can be exploited without user interaction if a crafted tif file is processed.