An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libgexiv2-develUpgrade libgexiv2Upgrade exiv2-docUpgrade gnome-color-managerUpgrade geglUpgrade exiv2-devel | May 4, 2022 | Jun 30, 2019 |
| Alpine Linux | — | Upgrade exiv2 | Jan 4, 2021 | Jun 30, 2019 |
| Centos_linux | — | Upgrade gegl-debugsourceUpgrade exiv2-libs-debuginfoUpgrade exiv2Upgrade libgexiv2-debuginfoUpgrade libgexiv2-debugsourceUpgrade exiv2-debuginfoUpgrade libgexiv2Upgrade gnome-color-managerUpgrade gegl-debuginfoUpgrade exiv2-debugsourceUpgrade gnome-color-manager-debuginfoUpgrade geglUpgrade gnome-color-manager-debugsourceUpgrade exiv2-libs | Apr 29, 2020 | Jun 30, 2019 |
| Debian | — | Upgrade exiv2 | Jul 30, 2024 | Jun 30, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade exiv2-libsUpgrade exiv2 | Apr 21, 2020 | Jun 30, 2019 |
| Oracle_linux | — | Upgrade exiv2-docUpgrade exiv2Upgrade geglUpgrade libgexiv2-develUpgrade gnome-color-managerUpgrade libgexiv2Upgrade exiv2-libsUpgrade exiv2-devel | Oct 5, 2022 | Jun 30, 2019 |
| Redhat_linux | — | Upgrade exiv2-debugsourceUpgrade exiv2-docUpgrade gnome-color-manager-debugsourceUpgrade gegl-debugsourceUpgrade gegl-debuginfoUpgrade geglUpgrade exiv2-develUpgrade exiv2-debuginfoUpgrade libgexiv2-debugsourceUpgrade exiv2-libs-debuginfoUpgrade gnome-color-manager-debuginfoUpgrade gnome-color-managerNo solution existsUpgrade libgexiv2-develUpgrade exiv2-libsUpgrade exiv2Upgrade libgexiv2Upgrade libgexiv2-debuginfo | Apr 29, 2020 | Jun 30, 2019 |
| Rocky_linux | — | Upgrade libgexiv2-debuginfoUpgrade gegl-debugsourceUpgrade exiv2-debuginfoUpgrade libgexiv2-debugsourceUpgrade exiv2Upgrade gnome-color-manager-debugsourceUpgrade exiv2-libs-debuginfoUpgrade exiv2-libsUpgrade gnome-color-managerUpgrade libgexiv2Upgrade gnome-color-manager-debuginfoUpgrade geglUpgrade libgexiv2-develUpgrade exiv2-debugsourceUpgrade gegl-debuginfoUpgrade exiv2-devel | Mar 12, 2024 | Jun 30, 2019 |
| Suse | — | Upgrade libexiv2-develUpgrade libexiv2-26-32bitUpgrade exiv2-langUpgrade exiv2Upgrade libexiv2-docUpgrade libexiv2-26 | Aug 9, 2024 | Jun 30, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub