REDHAT-BUG-1660426: Low severity centos dos2unix vulnerability
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack.
Upstream issue:
https://github.com/Exiv2/exiv2/issues/590
References:
https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1660426?
The vulnerability REDHAT-BUG-1660426 is classified as a denial of service due to an infinite loop.
How does REDHAT-BUG-1660426 affect Exiv2?
REDHAT-BUG-1660426 allows attackers to create crafted input that can lead to an infinite loop, causing application crashes.
How do I fix REDHAT-BUG-1660426?
Updating to a patched version of Exiv2 that addresses the infinite loop vulnerability will remedy REDHAT-BUG-1660426.
What version of Exiv2 is affected by REDHAT-BUG-1660426?
Exiv2 version 0.27-RC3 is specifically identified as being vulnerable in REDHAT-BUG-1660426.
Is REDHAT-BUG-1660426 exploitable remotely?
Yes, REDHAT-BUG-1660426 can potentially be exploited remotely if an attacker can provide the crafted input.