An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exiv2 | Feb 25, 2019 | Sep 28, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade exiv2-libs | Dec 4, 2019 | Sep 29, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade exiv2-libs | Dec 18, 2019 | Sep 29, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade exiv2-libs | Dec 27, 2019 | Sep 29, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 22, 2017 |
| Suse | — | Upgrade libexiv2-12Upgrade exiv2Upgrade libexiv2-26-32bitUpgrade exiv2-langUpgrade libexiv2-docUpgrade libexiv2-develUpgrade libexiv2-26 | May 20, 2018 | Sep 28, 2017 |
| Ubuntu | — | Upgrade libexiv2-14Upgrade exiv2Upgrade libexiv2-12 | Jan 17, 2019 | Sep 28, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub