First published: Tue Dec 18 2018(Updated: )
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack. Upstream issue: <a href="https://github.com/Exiv2/exiv2/issues/590">https://github.com/Exiv2/exiv2/issues/590</a> References: <a href="https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206">https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206</a>
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Dos2unix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1660424 is categorized as high due to its potential for causing a denial of service.
To fix REDHAT-BUG-1660424, update Exiv2 to the latest version where the issue has been resolved.
The software affected by REDHAT-BUG-1660424 is Exiv2 version 0.27-RC3.
REDHAT-BUG-1660424 enables denial of service attacks through crafted input specifically targeting the TiffParser.
REDHAT-BUG-1660424 was reported in December 2018.