REDHAT-BUG-1566737: Low severity exiv2 exiv2 vulnerability
Published Apr 12, 2018
·Updated
A flaw was found in Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the "!= 0x1c" case.
References: https://github.com/Exiv2/exiv2/issues/263 https://github.com/xiaoqx/pocs/blob/master/exiv2/readme.md
Affected Software
1 affected component
exiv2 exiv2
Event History
Apr 12, 2018
Data Sourced
via Red Hat·09:40 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1566737?
REDHAT-BUG-1566737 is classified as a medium severity vulnerability.
2
How do I fix REDHAT-BUG-1566737?
To fix REDHAT-BUG-1566737, update Exiv2 to the latest version that addresses the out-of-bounds read issue.
3
What systems are affected by REDHAT-BUG-1566737?
REDHAT-BUG-1566737 affects Exiv2 version 0.26 and possibly earlier versions.
4
What is the nature of the issue in REDHAT-BUG-1566737?
The issue in REDHAT-BUG-1566737 is an out-of-bounds read that could lead to a crash or an information leak.
5
Is there a known exploit for REDHAT-BUG-1566737?
As of now, there are no publicly available exploits specifically targeting REDHAT-BUG-1566737.