CVE-2018-8977: Buffer Overflow
Published Mar 25, 2018
·Updated
A flaw was found in Exiv2 0.26, the Exiv2::Internal::printCsLensFFFF function in canonmnint.cpp allows remote attackers to cause a denial of service (invalid memory access) via a crafted file.
References: https://github.com/Exiv2/exiv2/issues/247
Affected Software
1 affected component
exiv2 exiv2=0.26
Remediation
Patch Available
Event History
Mar 25, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 27, 2018
Data Sourced
via Red Hat·10:17 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8977?
CVE-2018-8977 is classified as a denial of service vulnerability due to an invalid memory access issue.
2
How do I fix CVE-2018-8977?
To fix CVE-2018-8977, update Exiv2 to a version that has addressed this vulnerability.
3
What systems are affected by CVE-2018-8977?
CVE-2018-8977 affects Exiv2 version 0.26.
4
Can CVE-2018-8977 be exploited remotely?
Yes, CVE-2018-8977 can be exploited remotely through crafted files.
5
What is the impact of CVE-2018-8977?
The impact of CVE-2018-8977 is a denial of service, which can disrupt the functionality of affected applications.