CVE-2020-18899: Medium severity centos dos2unix vulnerability
Published Aug 19, 2021
·Updated
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input.
Affected Software
1 affected component
exiv2 exiv2=0.27
Event History
Aug 19, 2021
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-18899?
CVE-2020-18899 has a severity level classified as medium due to its potential to cause denial of service.
2
How does CVE-2020-18899 exploit uncontrolled memory allocation?
CVE-2020-18899 exploits uncontrolled memory allocation by allowing attackers to craft input that results in excessive memory usage.
3
What software versions are affected by CVE-2020-18899?
CVE-2020-18899 specifically affects Exiv2 version 0.27.
4
How do I fix CVE-2020-18899?
To fix CVE-2020-18899, upgrade Exiv2 to a version later than 0.27 that addresses this vulnerability.
5
What is the impact of exploiting CVE-2020-18899?
Exploitation of CVE-2020-18899 can lead to denial of service, making the application unresponsive.