Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14982

Опубликовано: 14 июл. 2019
Источник: redhat
CVSS3: 4.3

Описание

In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can lead to a buffer overflow vulnerability and a crash.

An out-of-bounds read could happen when exiv2, or an application linked against the exiv2 library, is used to parse untrusted images in the WebP format. This flaw is caused by an integer wraparound in function WebPImage::getHeaderOffset, which could allow an attacker to crash the application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6exiv2Out of support scope
Red Hat Enterprise Linux 7exiv2Not affected
Red Hat Enterprise Linux 8exiv2Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1757909exiv2: integer overflow in the WebPImage::getHeaderOffset can lead to a out of bounds read

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can lead to a buffer overflow vulnerability and a crash.

CVSS3: 6.5
nvd
больше 6 лет назад

In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can lead to a buffer overflow vulnerability and a crash.

CVSS3: 6.5
debian
больше 6 лет назад

In Exiv2 before v0.27.2, there is an integer overflow vulnerability in ...

CVSS3: 6.5
github
больше 3 лет назад

In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can lead to a buffer overflow vulnerability and a crash.

CVSS3: 6.5
fstec
больше 6 лет назад

Уязвимость компонента webpimage.cpp библиотеки для управления метаданными медиафайлов Exiv2, позволяющая нарушителю вызвать отказ в обслуживании

4.3 Medium

CVSS3