First published: Thu Apr 12 2018(Updated: )
In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.cpp could result in a crash or information leak, due to use of the untrusted `len` value without any check. References: <a href="https://github.com/Exiv2/exiv2/issues/263">https://github.com/Exiv2/exiv2/issues/263</a> <a href="https://github.com/xiaoqx/pocs/blob/master/exiv2/readme.md">https://github.com/xiaoqx/pocs/blob/master/exiv2/readme.md</a>
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-1566735 is categorized as a medium severity vulnerability due to the potential for crashes or information leaks.
To fix REDHAT-BUG-1566735, it is recommended to update Exiv2 to a secure version where the out-of-bounds read issue has been addressed.
REDHAT-BUG-1566735 affects Exiv2 version 0.26.
The issue in REDHAT-BUG-1566735 is an out-of-bounds read vulnerability that arises from untrusted value usage in the code.
Yes, REDHAT-BUG-1566735 can lead to information leaks, posing a risk of data exposure.