CVE-2019-9143: High severity centos dos2unix vulnerability
Published Feb 25, 2019
·Updated
An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Affected Software
2 affected componentsFixes available
redhat/exiv2<0.27
0.27
exiv2 exiv2=0.27
Event History
Feb 25, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9143?
CVE-2019-9143 has a severity level that allows for Denial of Service attacks due to infinite recursion leading to segmentation faults.
2
How do I fix CVE-2019-9143?
To remediate CVE-2019-9143, update Exiv2 to a version higher than 0.27.
3
What types of attacks can CVE-2019-9143 enable?
CVE-2019-9143 can be exploited to launch Denial of Service attacks by causing an application crash.
4
What software versions are affected by CVE-2019-9143?
CVE-2019-9143 affects Exiv2 version 0.27.
5
Is CVE-2019-9143 specific to any operating systems?
CVE-2019-9143 is relevant to any system that runs Exiv2 version 0.27, regardless of the operating system.