First published: Mon Feb 25 2019(Updated: )
An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | =0.27 | |
redhat/exiv2 | <0.27 | 0.27 |
=0.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9143 has a severity level that allows for Denial of Service attacks due to infinite recursion leading to segmentation faults.
To remediate CVE-2019-9143, update Exiv2 to a version higher than 0.27.
CVE-2019-9143 can be exploited to launch Denial of Service attacks by causing an application crash.
CVE-2019-9143 affects Exiv2 version 0.27.
CVE-2019-9143 is relevant to any system that runs Exiv2 version 0.27, regardless of the operating system.