CVE-2019-13114: Null Pointer Dereference
A vulnerability was discovered in http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
Reference: https://github.com/Exiv2/exiv2/issues/793 https://github.com/Exiv2/exiv2/pull/815
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13114?
CVE-2019-13114 is rated as a denial of service vulnerability due to potential crashes from a NULL pointer dereference.
How do I fix CVE-2019-13114?
To mitigate CVE-2019-13114, upgrade Exiv2 to version 0.27.2 or later.
What systems are affected by CVE-2019-13114?
CVE-2019-13114 affects Exiv2 versions up to 0.27.1 and various Linux distributions including Red Hat and Debian.
Can CVE-2019-13114 be exploited remotely?
Yes, CVE-2019-13114 can be exploited by a malicious HTTP server providing a crafted response.
What happens if I do not patch CVE-2019-13114?
Failure to patch CVE-2019-13114 may result in application crashes and service interruptions.