First published: Sun Mar 25 2018(Updated: )
In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | =0.26 | |
Debian Debian Linux | =10.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8976 has been classified as a denial of service vulnerability.
To fix CVE-2018-8976, update Exiv2 to a version that has patched the vulnerability.
CVE-2018-8976 affects Exiv2 version 0.26, as well as certain versions of Debian and Red Hat Enterprise Linux.
Yes, CVE-2018-8976 can be exploited remotely through crafted image files.
CVE-2018-8976 represents an attack that leads to denial of service due to an out-of-bounds read.