Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-17723

Опубликовано: 10 дек. 2017
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp. Remote attackers can exploit this vulnerability to disclose memory data or cause a denial of service via a crafted TIFF file.

An integer wraparound, leading to heap-based out-of-bound read, was found in the way Exiv2 library prints Image File Directory(IFD) in TIFF images. By persuading a victim to open a crafted TIFF image, a remote attacker could crash the application or possibly retrieve a portion of memory.

Отчет

This issue did not affect the versions of Exiv2 as shipped with Red Hat Enterprise Linux 6 and 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6exiv2Not affected
Red Hat Enterprise Linux 7exiv2Not affected
Red Hat Enterprise Linux 8exiv2Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1545249exiv2: heap-based buffer over-read in Exiv2::Image::byteSwap4 in image.cpp

EPSS

Процентиль: 69%
0.0061
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 8 лет назад

In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp. Remote attackers can exploit this vulnerability to disclose memory data or cause a denial of service via a crafted TIFF file.

CVSS3: 8.1
nvd
почти 8 лет назад

In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp. Remote attackers can exploit this vulnerability to disclose memory data or cause a denial of service via a crafted TIFF file.

CVSS3: 8.1
debian
почти 8 лет назад

In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Im ...

CVSS3: 8.1
github
больше 3 лет назад

In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp. Remote attackers can exploit this vulnerability to disclose memory data or cause a denial of service via a crafted TIFF file.

EPSS

Процентиль: 69%
0.0061
Низкий

4.4 Medium

CVSS3