REDHAT-BUG-1660424: Low severity centos dos2unix vulnerability
Published Dec 18, 2018
·Updated
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimageint.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack.
Upstream issue:
https://github.com/Exiv2/exiv2/issues/590
References:
https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206
Affected Software
1 affected component
exiv2 exiv2
Event History
Dec 18, 2018
Data Sourced
via Red Hat·10:10 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1660424?
The severity of REDHAT-BUG-1660424 is categorized as high due to its potential for causing a denial of service.
2
How do I fix REDHAT-BUG-1660424?
To fix REDHAT-BUG-1660424, update Exiv2 to the latest version where the issue has been resolved.
3
What software is affected by REDHAT-BUG-1660424?
The software affected by REDHAT-BUG-1660424 is Exiv2 version 0.27-RC3.
4
What types of attacks does REDHAT-BUG-1660424 enable?
REDHAT-BUG-1660424 enables denial of service attacks through crafted input specifically targeting the TiffParser.
5
When was REDHAT-BUG-1660424 reported?
REDHAT-BUG-1660424 was reported in December 2018.