First published: Thu Apr 12 2018(Updated: )
A flaw was found in Exiv2 0.26, an assertion failure in BigTiffImage::readData in bigtiffimage.cpp results in an abort. References: <a href="https://github.com/xiaoqx/pocs/blob/master/exiv2/readme.md">https://github.com/xiaoqx/pocs/blob/master/exiv2/readme.md</a>
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1566725 is classified as a critical vulnerability due to the potential for application aborts.
To fix REDHAT-BUG-1566725, upgrade Exiv2 to the latest patched version provided by the vendor.
REDHAT-BUG-1566725 specifically affects Exiv2 versions prior to the latest release.
REDHAT-BUG-1566725 is an assertion failure issue in the BigTiffImage::readData function.
Yes, REDHAT-BUG-1566725 can potentially be exploited remotely if the vulnerable Exiv2 application is accessible over the network.