First published: Mon Feb 25 2019(Updated: )
An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in the file bigtiffimage.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | =0.27 | |
=0.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9144 has been classified as a Denial of Service vulnerability due to its ability to cause segmentation faults through infinite recursion.
To mitigate CVE-2019-9144, it is recommended to upgrade Exiv2 to a newer version that addresses this vulnerability.
CVE-2019-9144 can lead to Denial of Service conditions or potentially unspecified impacts due to the crafted file triggering infinite recursion.
CVE-2019-9144 is present in Exiv2 version 0.27.
An attacker can exploit CVE-2019-9144 by providing a crafted BigTIFF file that generates infinite recursion during processing.