First published: Mon Oct 01 2018(Updated: )
A flaw was found in Exiv2 0.26. The CiffDirectory::readDirectory() function at crwimage_int.cpp has an excessive stack consumption due to a recursive function, leading to Denial of service. References: <a href="https://github.com/Exiv2/exiv2/issues/460">https://github.com/Exiv2/exiv2/issues/460</a> <a href="https://github.com/SegfaultMasters/covering360/blob/master/Exiv2">https://github.com/SegfaultMasters/covering360/blob/master/Exiv2</a>
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1635045 is classified as a Denial of Service due to excessive stack consumption.
To fix REDHAT-BUG-1635045, update Exiv2 to a version that addresses the stack consumption vulnerability.
Exiv2 version 0.26 is affected by the vulnerability described in REDHAT-BUG-1635045.
REDHAT-BUG-1635045 is a Denial of Service vulnerability caused by excessive stack consumption in a recursive function.
If using an affected version of Exiv2, it is recommended to upgrade to a patched version to mitigate the vulnerability.