Описание
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
Отчет
Red Hat Product Security has determined the Impact to this bug as low for the following reasons:
- The attacker needs access to the system to trigger the bug as exiv2 is a library accompanied by a command line utility.
- While it is possible to crash exiv2 with a malicious payload, there is no known exploit to be able to run arbitrary code or escalate privileges. This only creates an availability problem.
- The bug does not affect any other resources in terms of integrity, confidentiality or avialability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | exiv2 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | compat-exiv2-023 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | compat-exiv2-026 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | exiv2 | Out of support scope | ||
| Red Hat Enterprise Linux 8 | compat-exiv2-026 | Will not fix | ||
| Red Hat Enterprise Linux 8 | exiv2 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | exiv2 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
3.5 Low
CVSS3
Связанные уязвимости
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Niko ...
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
Уязвимость функции Exiv2::Internal::Nikon1MakerNote::print0x0088 компонента nikonmn_int.cpp библиотеки для управления метаданными медиафайлов Exiv2, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
3.5 Low
CVSS3