PT-2019-6171 · Exiv2+6 · Exiv2+6

CVE-2020-18898

·

Publicado

2019-03-13

·

Atualizado

2022-10-26

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 version 0.27
Description The issue is related to a stack exhaustion problem in the printIFDStructure function of the Exiv2 library. This allows a remote attacker to cause a denial of service (DOS) by using a specially crafted file. The exploitation of this issue can lead to a service disruption.
Recommendations For Exiv2 version 0.27, consider disabling the printIFDStructure function as a temporary workaround until a patch is available. Restrict access to the Exiv2 library to minimize the risk of exploitation. Avoid using the Exiv2 library with untrusted files until the issue is resolved.

Exploit

Correção

DoS

Uncontrolled Recursion

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2022:1797
ALSA-2022:1842
BDU:2022-01660
CESA-2022_1797
CESA-2022_1842
CVE-2020-18898
OPENSUSE-SU-2022_3598-1
RHSA-2022:1797
RHSA-2022:1842
RHSA-2022_1797
RHSA-2022_1842
RLSA-2022:1797
RLSA-2022:1842
SUSE-SU-2022:3598-1

Produtos afetados

Almalinux
Centos
Debian
Exiv2
Red Hat
Rocky Linux
Suse