First published: Fri Mar 30 2018(Updated: )
In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp. It could result in denial of service or information disclosure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix | <0.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9144 has a medium severity level as it can lead to denial of service or information disclosure.
To fix CVE-2018-9144, update to Exiv2 version 0.26 or later.
CVE-2018-9144 affects Exiv2 versions prior to 0.26.
CVE-2018-9144 is an out-of-bounds read vulnerability that can result in denial of service or information disclosure.
Yes, CVE-2018-9144 could potentially be exploited remotely, depending on how the affected software is used.