Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-18898

Опубликовано: 19 авг. 2021
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.

The exiv2 program is susceptible to a stack exhaustion issue via a crafted file. The cause of this vulnerability, is due to a flaw in the code which could allow remote attackers to cause a denial of service (DOS). The highest threat from this vulnerability is availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6exiv2Out of support scope
Red Hat Enterprise Linux 7compat-exiv2-023Out of support scope
Red Hat Enterprise Linux 7compat-exiv2-026Out of support scope
Red Hat Enterprise Linux 7exiv2Out of support scope
Red Hat Enterprise Linux 9exiv2Not affected
Red Hat Enterprise Linux 8compat-exiv2-026FixedRHSA-2022:179710.05.2022
Red Hat Enterprise Linux 8exiv2FixedRHSA-2022:184210.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2002678exiv2: stack exhaustion issue in the printIFDStructure function may lead to DoS

EPSS

Процентиль: 37%
0.00158
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.

CVSS3: 6.5
nvd
почти 4 года назад

A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.

CVSS3: 6.5
debian
почти 4 года назад

A stack exhaustion issue in the printIFDStructure function of Exiv2 0. ...

rocky
около 3 лет назад

Moderate: exiv2 security, bug fix, and enhancement update

rocky
около 3 лет назад

Moderate: compat-exiv2-026 security update

EPSS

Процентиль: 37%
0.00158
Низкий

6.5 Medium

CVSS3