First published: Sun Jul 28 2019(Updated: )
Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | =0.27.99.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14368 is classified as a high severity vulnerability due to the potential for exploiting a heap-based buffer over-read.
To fix CVE-2019-14368, upgrade Exiv2 to version 0.27.99.1 or later which contains the relevant security patches.
The impact of CVE-2019-14368 includes potential unauthorized access to sensitive data through heap-based buffer over-reads.
CVE-2019-14368 affects Exiv2 version 0.27.99.0 specifically.
There is currently no public information indicating that CVE-2019-14368 is being actively exploited in the wild.