CVE-2019-9143

An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
Affected Products (NVD)
VendorProductVersion
exiv2exiv2
0.27
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
exiv2
bookworm
0.27.6-1
fixed
bullseye
0.27.3-3+deb11u2
fixed
bullseye (security)
0.27.3-3+deb11u1
fixed
buster
not-affected
jessie
not-affected
sid
0.28.3+dfsg-2
fixed
stretch
not-affected
trixie
0.28.3+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
exiv2
bionic
not-affected
cosmic
not-affected
trusty
dne
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
exiv2
RHEL 7
0:0.27.0-2.el7_6
fixed
RHEL 8
0:0.27.2-5.el8
fixed
exiv2-devel
RHEL 7
0:0.27.0-2.el7_6
fixed
RHEL 8
0:0.27.2-5.el8
fixed
exiv2-doc
RHEL 7
0:0.27.0-2.el7_6
fixed
RHEL 8
0:0.27.2-5.el8
fixed
exiv2-libs
RHEL 7
0:0.27.0-2.el7_6
fixed
RHEL 8
0:0.27.2-5.el8
fixed
gegl
RHEL 8
0:0.2.0-39.el8
fixed
gnome-color-manager
RHEL 8
0:3.28.0-3.el8
fixed
libgexiv2
RHEL 8
0:0.10.8-4.el8
fixed
libgexiv2-devel
RHEL 8
0:0.10.8-4.el8
fixed