Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pvvg-cg5r-2q8v

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

EPSS

Процентиль: 64%
0.00468
Низкий

8.8 High

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 7 лет назад

An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVSS3: 4
redhat
почти 7 лет назад

An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVSS3: 8.8
nvd
почти 7 лет назад

An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVSS3: 8.8
debian
почти 7 лет назад

An issue was discovered in Exiv2 0.27. There is infinite recursion at ...

rocky
больше 5 лет назад

Moderate: exiv2 security, bug fix, and enhancement update

EPSS

Процентиль: 64%
0.00468
Низкий

8.8 High

CVSS3

Дефекты

CWE-674