First published: Tue Dec 04 2018(Updated: )
An issue was found in Exiv2 0.26 and previous versions. A heap-based buffer over-read in PngChunk::readRawProfile function in pngchunk_int.cpp may cause a denial of service via a crafted PNG file. References: <a href="https://github.com/Exiv2/exiv2/issues/428">https://github.com/Exiv2/exiv2/issues/428</a> <a href="https://github.com/Exiv2/exiv2/pull/430">https://github.com/Exiv2/exiv2/pull/430</a>
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix | <0.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1656187 is classified as a denial of service vulnerability.
To fix REDHAT-BUG-1656187, upgrade to Exiv2 version 0.26 or later.
The vulnerability in REDHAT-BUG-1656187 is caused by a heap-based buffer over-read in the PngChunk::readRawProfile function.
Exiv2 versions prior to 0.26 are affected by REDHAT-BUG-1656187.
The potential impact of REDHAT-BUG-1656187 is a denial of service via crafted PNG files.