CVE-2018-20097
12.12.2018, 10:29
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| exiv2 | exiv2 | 0.27:rc3 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 10.0 |
| redhat | enterprise_linux_dekstop | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_workstation | 7.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libexiv2-26 |
| ||||||||||||||||||
| libexiv2-devel |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| exiv2 |
| ||||
| exiv2-devel |
| ||||
| exiv2-doc |
| ||||
| exiv2-libs |
| ||||
| gegl |
| ||||
| gnome-color-manager |
| ||||
| libgexiv2 |
| ||||
| libgexiv2-devel |
|
Common Weakness Enumeration
References