First published: Thu Aug 19 2021(Updated: )
A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix | =0.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-18898 has a medium severity due to its potential to cause denial of service through stack exhaustion.
To resolve CVE-2020-18898, upgrade Exiv2 to version 0.27.1 or above, where the vulnerability has been addressed.
Exiv2 version 0.27 is affected by CVE-2020-18898.
CVE-2020-18898 is associated with a denial of service attack that can be triggered by maliciously crafted files.
The printIFDStructure function in Exiv2 is the key function involved in the stack exhaustion issue described in CVE-2020-18898.