An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exiv2 | Feb 25, 2019 | Sep 28, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade exiv2-libs | Dec 4, 2019 | Sep 29, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade exiv2-libs | Dec 18, 2019 | Sep 29, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade exiv2-libs | Dec 27, 2019 | Sep 29, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 23, 2017 |
| Suse | — | Upgrade libexiv2-26-32bitUpgrade libexiv2-docUpgrade libexiv2-develUpgrade libexiv2-26Upgrade exiv2Upgrade libexiv2-12Upgrade exiv2-lang | Oct 20, 2017 | Sep 28, 2017 |
| Ubuntu | — | Upgrade libexiv2-12Upgrade libexiv2-14Upgrade exiv2 | Jan 17, 2019 | Sep 28, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub