There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exiv2 | Feb 25, 2019 | Jul 27, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade exiv2-libs | Dec 4, 2019 | Jul 27, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade exiv2-libs | Dec 18, 2019 | Jul 27, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade exiv2-libs | Dec 27, 2019 | Jul 27, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 26, 2017 |
| Suse | — | Upgrade libexiv2-26-32bitUpgrade libexiv2-develUpgrade libexiv2-12Upgrade exiv2Upgrade exiv2-langUpgrade libexiv2-docUpgrade libexiv2-26 | Oct 20, 2017 | Jul 27, 2017 |
| Ubuntu | — | Upgrade libexiv2-12Upgrade exiv2Upgrade libexiv2-14 | Jan 17, 2019 | Jul 27, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub