REDHAT-BUG-1646555: Low severity centos dos2unix vulnerability
A flaw was found in Exiv2 0.27-RC1. An infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp. A crafted input will lead to a remote denial of service attack.
References: https://github.com/Exiv2/exiv2/issues/511
Upstream Patch: https://github.com/Exiv2/exiv2/pull/517
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1646555?
The severity of REDHAT-BUG-1646555 is critical due to the potential for remote denial of service attacks.
How do I fix REDHAT-BUG-1646555?
To fix REDHAT-BUG-1646555, you should upgrade Exiv2 to a version that has addressed this vulnerability.
What causes the issue in REDHAT-BUG-1646555?
The issue in REDHAT-BUG-1646555 is caused by an infinite loop in the Exiv2::Image::printIFDStructure function.
Who is affected by REDHAT-BUG-1646555?
Users of Exiv2 0.27-RC1 and earlier versions are affected by the vulnerability described in REDHAT-BUG-1646555.
What are the potential impacts of REDHAT-BUG-1646555?
The potential impacts of REDHAT-BUG-1646555 include service interruption and resource exhaustion due to the denial of service condition.