First published: Sun Mar 25 2018(Updated: )
In Exiv2 0.26, the Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp allows remote attackers to cause a denial of service (invalid memory access) via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | =0.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8977 is classified as a denial of service vulnerability due to an invalid memory access issue.
To fix CVE-2018-8977, update Exiv2 to a version that has addressed this vulnerability.
CVE-2018-8977 affects Exiv2 version 0.26.
Yes, CVE-2018-8977 can be exploited remotely through crafted files.
The impact of CVE-2018-8977 is a denial of service, which can disrupt the functionality of affected applications.