First published: Wed Apr 04 2018(Updated: )
In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the "== 0x1c" case.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | <0.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9305 is considered to have medium severity due to the potential for crashes and information leaks.
To fix CVE-2018-9305, update Exiv2 to the latest version beyond 0.26 that addresses this vulnerability.
CVE-2018-9305 affects Exiv2 versions prior to 0.26.
The potential consequences of CVE-2018-9305 include application crashes and exposure of sensitive information.
Exploitation of CVE-2018-9305 may require specific inputs to trigger the out-of-bounds read, making it moderately difficult to exploit.