Exiv2 'image. cpp 'Remote Denial of Service Vulnerability (CVE-2018-5772)
Exiv2 'image. cpp 'Remote Denial of Service Vulnerability (CVE-2018-5772)
Release date:
Updated on:
Affected Systems:
Exiv2 Exiv2 0.26
Description:
Bugtraq id: 102789
CVE (CAN) ID: CVE-2018-5772
Exiv2 is a C ++ class library used to extract the EXIF, LPTC, and XMP metadata information in the image.
Exiv2 0.26, Exiv2: Image: printIFDStructure function has uncontrolled recursion, which may cause segmentation errors. Remote attackers can construct tif files to cause DOS.
<* Source: ProbeFuzzer
*>
Suggestion:
Vendor patch:
Exiv2
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1536904
Https://access.redhat.com/security/cve/cve-2018-5772
Http://dev.exiv2.org/projects/exiv2
Https://github.com/Exiv2/exiv2/issues/216