REDHAT-BUG-1649101: Integer Overflow
A flaw was found in Exiv2 0.26. An infinite loop in Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader. This could lead to a denial of service caused by an integer overflow via a crafted PSD image file.
References: https://github.com/Exiv2/exiv2/issues/426
Upstream Patch: https://github.com/Exiv2/exiv2/pull/518
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1649101?
The vulnerability has the potential to cause a denial of service due to an infinite loop in the Exiv2 PSD image reader.
How do I fix REDHAT-BUG-1649101?
To mitigate REDHAT-BUG-1649101, update Exiv2 to the latest version where the issue has been resolved.
What is affected by REDHAT-BUG-1649101?
The vulnerability affects Exiv2 version 0.26 specifically when processing crafted PSD image files.
What type of attack is associated with REDHAT-BUG-1649101?
The vulnerability is associated with denial of service attacks due to an infinite loop triggered by a specially crafted file.
Can I exploit REDHAT-BUG-1649101 remotely?
Yes, an attacker can exploit this vulnerability remotely by sending a malicious PSD image file.