CVE-2020-18898: Medium severity centos dos2unix vulnerability
Published Aug 19, 2021
·Updated
A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.
Affected Software
1 affected component
exiv2 exiv2=0.27
Event History
Aug 19, 2021
CVE Published
via MITRE·09:20 PM
Data Sourced
via MITRE·09:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-18898?
CVE-2020-18898 has a medium severity due to its potential to cause denial of service through stack exhaustion.
2
How do I fix CVE-2020-18898?
To resolve CVE-2020-18898, upgrade Exiv2 to version 0.27.1 or above, where the vulnerability has been addressed.
3
Which versions of Exiv2 are affected by CVE-2020-18898?
Exiv2 version 0.27 is affected by CVE-2020-18898.
4
What type of attack is associated with CVE-2020-18898?
CVE-2020-18898 is associated with a denial of service attack that can be triggered by maliciously crafted files.
5
What is the key function involved in CVE-2020-18898?
The printIFDStructure function in Exiv2 is the key function involved in the stack exhaustion issue described in CVE-2020-18898.