CVE-2018-9304: Divide by Zero
Published Apr 4, 2018
·Updated
A flaw was found in Exiv2 0.26, a divide by zero in BigTiffImage::printIFD in bigtiffimage.cpp could result in denial of service.
References: https://github.com/Exiv2/exiv2/issues/262 https://github.com/xiaoqx/pocs/blob/master/exiv2/readme.md
Affected Software
1 affected component
exiv2 exiv2<0.26
Remediation
Patch Available
Event History
Apr 4, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 12, 2018
Data Sourced
via Red Hat·09:30 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9304?
CVE-2018-9304 has a severity rating that indicates it can lead to denial of service.
2
How do I fix CVE-2018-9304?
To fix CVE-2018-9304, upgrade Exiv2 to version 0.26 or higher.
3
What software is affected by CVE-2018-9304?
CVE-2018-9304 affects Exiv2 versions prior to 0.26.
4
What type of vulnerability is CVE-2018-9304?
CVE-2018-9304 is a divide by zero vulnerability in the Exiv2 software.
5
What impact does CVE-2018-9304 have on my system?
The impact of CVE-2018-9304 may result in a denial of service condition on systems using the affected Exiv2 software.