CVE-2018-19535
26.11.2018, 02:29
In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-based buffer over-read) via a crafted PNG file.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| exiv2 | exiv2 | 𝑥 ≤ 0.26 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 10.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| canonical | ubuntu_linux | 19.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| exiv2 |
| ||||
| exiv2-devel |
| ||||
| exiv2-doc |
| ||||
| exiv2-libs |
| ||||
| gegl |
| ||||
| gnome-color-manager |
| ||||
| libgexiv2 |
| ||||
| libgexiv2-devel |
|
Common Weakness Enumeration
References