Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hmv7-h8ff-46mm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.

A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.

EPSS

Процентиль: 27%
0.0009
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 6 лет назад

A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.

CVSS3: 3.3
redhat
около 6 лет назад

A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.

CVSS3: 5.5
nvd
около 6 лет назад

A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.

CVSS3: 5.5
debian
около 6 лет назад

A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 all ...

suse-cvrf
почти 3 года назад

Security update for exiv2

EPSS

Процентиль: 27%
0.0009
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-190