REDHAT-BUG-1656187: Low severity centos dos2unix vulnerability
Published Dec 4, 2018
·Updated
An issue was found in Exiv2 0.26 and previous versions. A heap-based buffer over-read in PngChunk::readRawProfile function in pngchunkint.cpp may cause a denial of service via a crafted PNG file.
References: https://github.com/Exiv2/exiv2/issues/428 https://github.com/Exiv2/exiv2/pull/430
Affected Software
1 affected component
exiv2 exiv2<0.26
Event History
Dec 4, 2018
Data Sourced
via Red Hat·10:04 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1656187?
The severity of REDHAT-BUG-1656187 is classified as a denial of service vulnerability.
2
How do I fix REDHAT-BUG-1656187?
To fix REDHAT-BUG-1656187, upgrade to Exiv2 version 0.26 or later.
3
What causes the vulnerability in REDHAT-BUG-1656187?
The vulnerability in REDHAT-BUG-1656187 is caused by a heap-based buffer over-read in the PngChunk::readRawProfile function.
4
Which versions of Exiv2 are affected by REDHAT-BUG-1656187?
Exiv2 versions prior to 0.26 are affected by REDHAT-BUG-1656187.
5
What is the potential impact of REDHAT-BUG-1656187?
The potential impact of REDHAT-BUG-1656187 is a denial of service via crafted PNG files.