First published: Tue Dec 04 2018(Updated: )
An issue was found in Exiv2 v0.27-RC2. A NULL pointer dereference in Exiv2::isoSpeed in easyaccess.cpp allows remote attackers to cause a denial of service via a crafted file. References: <a href="https://github.com/Exiv2/exiv2/issues/561">https://github.com/Exiv2/exiv2/issues/561</a>
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1656195 is classified as a denial of service vulnerability.
To fix REDHAT-BUG-1656195, update to a patched version of Exiv2 that addresses the NULL pointer dereference issue.
REDHAT-BUG-1656195 affects Exiv2 version 0.27-RC2.
Yes, REDHAT-BUG-1656195 can be exploited remotely through crafted files.
REDHAT-BUG-1656195 is a NULL pointer dereference vulnerability.