First published: Mon Aug 12 2019(Updated: )
In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can lead to a buffer overflow vulnerability and a crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix | <0.27.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14982 has been classified as a medium severity vulnerability due to the potential for a buffer overflow.
To fix CVE-2019-14982, update Exiv2 to version 0.27.2 or later.
CVE-2019-14982 is caused by an integer overflow in the WebPImage::getHeaderOffset function.
The potential impacts of CVE-2019-14982 include application crashes and possible exploitation leading to arbitrary code execution.
All versions of Exiv2 prior to version 0.27.2 are affected by CVE-2019-14982.