CVE-2019-9144: High severity centos dos2unix vulnerability
An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in the file bigtiffimage.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9144?
CVE-2019-9144 has been classified as a Denial of Service vulnerability due to its ability to cause segmentation faults through infinite recursion.
How do I fix CVE-2019-9144?
To mitigate CVE-2019-9144, it is recommended to upgrade Exiv2 to a newer version that addresses this vulnerability.
What impacts can be caused by CVE-2019-9144?
CVE-2019-9144 can lead to Denial of Service conditions or potentially unspecified impacts due to the crafted file triggering infinite recursion.
In which version of Exiv2 is CVE-2019-9144 present?
CVE-2019-9144 is present in Exiv2 version 0.27.
How can an attacker exploit CVE-2019-9144?
An attacker can exploit CVE-2019-9144 by providing a crafted BigTIFF file that generates infinite recursion during processing.