Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-9145

Опубликовано: 03 апр. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6exiv2Not affected
Red Hat Enterprise Linux 7exiv2Not affected
Red Hat Enterprise Linux 8exiv2Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1564281exiv2: reachable assertion abort in the function Exiv2::DataBuf::DataBuf at include/exiv2/types.hpp

EPSS

Процентиль: 57%
0.00348
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 8 лет назад

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.

CVSS3: 6.5
nvd
почти 8 лет назад

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.

CVSS3: 6.5
debian
почти 8 лет назад

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issu ...

CVSS3: 6.5
github
больше 3 лет назад

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.

EPSS

Процентиль: 57%
0.00348
Низкий

3.3 Low

CVSS3

Уязвимость CVE-2018-9145