PT-2018-17137 · Exiv2+2 · Exiv2+2

·

CVE-2018-5772

·

Published

2018-01-18

·

Updated

2022-10-17

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Exiv2 version 0.26
Description: The issue is caused by uncontrolled recursion in the Exiv2::Image::printIFDStructure function, located in the image.cpp file. This can be exploited by remote attackers to cause a denial of service using a crafted tif file.
Recommendations: For Exiv2 version 0.26, consider disabling the Exiv2::Image::printIFDStructure function until a patch is available to prevent potential denial of service attacks via crafted tif files.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2105
ALT-PU-2019-2468
ALT-PU-2019-2590
CVE-2018-5772
OPENSUSE-SU-2022_3598-1
SUSE-SU-2022:3598-1

Affected Products

Alt Linux
Exiv2
Suse