Exiv2 Heap Buffer Overflow Vulnerability (CVE-2017-17669)
Exiv2 Heap Buffer Overflow Vulnerability (CVE-2017-17669)
Release date:
Updated on:
Affected Systems:
Exiv2 Exiv2 0.26
Description:
Bugtraq id: 102265
CVE (CAN) ID: CVE-2017-17669
Exiv2 is a C ++ class library used to extract the EXIF, LPTC, and XMP metadata information in the image.
Exiv2 0.26, pngchunk_int.cpp/Exiv2: Internal: PngChunk: keyTXTChunk function has the heap buffer overflow vulnerability. Attackers can exploit this vulnerability to cause Remote DoS by constructing PNG files.
<* Source: Young_X @ VARAS
*>
Suggestion:
Vendor patch:
Exiv2
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://github.com/Exiv2/exiv2/issues/187
Http://dev.exiv2.org/projects/exiv2
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1526052
Https://access.redhat.com/security/cve/CVE-2017-17669