Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade exiv2-develUpgrade exiv2-doc | May 4, 2022 | Oct 9, 2019 |
| Alpine Linux | — | Upgrade exiv2 | Dec 27, 2019 | Oct 9, 2019 |
| Amazon Linux Ami 2 | — | Upgrade exiv2-docUpgrade exiv2Upgrade exiv2-debuginfoUpgrade exiv2-libsUpgrade exiv2-devel | Oct 28, 2020 | Oct 9, 2019 |
| Centos_linux | — | Upgrade exiv2-docUpgrade exiv2-debugsourceUpgrade exiv2-develUpgrade exiv2Upgrade exiv2-debuginfoUpgrade exiv2-libsUpgrade exiv2-libs-debuginfo | Oct 1, 2020 | Oct 9, 2019 |
| Debian | — | Upgrade exiv2 | Dec 4, 2019 | Oct 9, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade exiv2-libs | Sep 16, 2021 | Oct 9, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade exiv2-libs | Apr 30, 2021 | Oct 9, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade exiv2-libs | Mar 24, 2021 | Oct 9, 2019 |
| Oracle_linux | — | Upgrade exiv2-docUpgrade exiv2Upgrade exiv2-develUpgrade exiv2-libs | Oct 7, 2020 | Oct 6, 2019 |
| Redhat_linux | — | Upgrade exiv2-debugsourceUpgrade exiv2-develNo solution existsUpgrade exiv2-libs-debuginfoUpgrade exiv2Upgrade exiv2-doc | Oct 1, 2020 | Oct 9, 2019 |
| Rocky_linux | — | Upgrade exiv2-libs-debuginfoUpgrade exiv2Upgrade exiv2-libsUpgrade exiv2-develUpgrade exiv2-debuginfoUpgrade exiv2-debugsource | Mar 12, 2024 | Oct 9, 2019 |
| Suse | — | Upgrade libexiv2-develUpgrade libexiv2-12 | Apr 4, 2020 | Oct 9, 2019 |
| Ubuntu | — | Upgrade libexiv2-14Upgrade exiv2 | Oct 22, 2019 | Oct 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub