exiv2 0.26 contains a Stack out of bounds read in webp parser
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Huawei Euleros 2_0_sp5 | — | Upgrade exiv2-libs | Nov 19, 2019 | Nov 17, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 30, 2017 |
| Suse | — | Upgrade libexiv2-develUpgrade libexiv2-26-32bitUpgrade libexiv2-docUpgrade libexiv2-26Upgrade exiv2Upgrade exiv2-lang | Apr 9, 2020 | Nov 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub