An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exiv2 | May 29, 2017 | May 26, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade exiv2-libs | Dec 4, 2019 | May 26, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade exiv2-libs | Dec 18, 2019 | May 26, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 25, 2017 |
| Suse | — | Upgrade libexiv2-docUpgrade libexiv2-26Upgrade libexiv2-26-32bitUpgrade libexiv2-12Upgrade libexiv2-develUpgrade exiv2Upgrade exiv2-lang | Apr 4, 2020 | May 26, 2017 |
| Ubuntu | — | Upgrade libexiv2-14Upgrade libexiv2-12Upgrade exiv2 | Jan 17, 2019 | May 26, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub