First published: Thu Aug 19 2021(Updated: )
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix | =0.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-18899 has a severity level classified as medium due to its potential to cause denial of service.
CVE-2020-18899 exploits uncontrolled memory allocation by allowing attackers to craft input that results in excessive memory usage.
CVE-2020-18899 specifically affects Exiv2 version 0.27.
To fix CVE-2020-18899, upgrade Exiv2 to a version later than 0.27 that addresses this vulnerability.
Exploitation of CVE-2020-18899 can lead to denial of service, making the application unresponsive.