Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 30, 2017 |
| Suse | — | Upgrade libexiv2-26-32bitUpgrade exiv2-langUpgrade libexiv2-26Upgrade libexiv2-develUpgrade libexiv2-27Upgrade libexiv2-27-32bitUpgrade libexiv2-xmp-staticUpgrade exiv2 | Aug 9, 2024 | Nov 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub