CVE-2018-8976: Medium severity exiv2 exiv2 vulnerability
Published Mar 25, 2018
·Updated
A flaw was found in Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a crafted file.
References: https://github.com/Exiv2/exiv2/issues/246
Affected Software
5 affected components
exiv2 exiv2=0.26
Debian Debian Linux=10.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=7.0
Remediation
Patch Available
Event History
Mar 25, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 27, 2018
Data Sourced
via Red Hat·10:10 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8976?
CVE-2018-8976 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2018-8976?
To fix CVE-2018-8976, update Exiv2 to a version that has patched the vulnerability.
3
What software does CVE-2018-8976 affect?
CVE-2018-8976 affects Exiv2 version 0.26, as well as certain versions of Debian and Red Hat Enterprise Linux.
4
Can CVE-2018-8976 be exploited remotely?
Yes, CVE-2018-8976 can be exploited remotely through crafted image files.
5
What type of attack does CVE-2018-8976 represent?
CVE-2018-8976 represents an attack that leads to denial of service due to an out-of-bounds read.