An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-exiv2 | Feb 25, 2019 | Sep 28, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-exiv2-libs | Dec 4, 2019 | Sep 29, 2017 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-exiv2-libs | Dec 18, 2019 | Sep 29, 2017 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-exiv2-libs | Dec 27, 2019 | Sep 29, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Sep 23, 2017 | |
| Suse | — | suse-upgrade-exiv2suse-upgrade-exiv2-langsuse-upgrade-libexiv2-12suse-upgrade-libexiv2-26suse-upgrade-libexiv2-26-32bitsuse-upgrade-libexiv2-develsuse-upgrade-libexiv2-doc | Oct 20, 2017 | Sep 28, 2017 |
| Ubuntu | ubuntu-upgrade-exiv2ubuntu-upgrade-libexiv2-12ubuntu-upgrade-libexiv2-14 | Jan 17, 2019 | Sep 28, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub