Описание
There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | released | 0.25-3.1ubuntu0.18.04.2 |
| cosmic | released | 0.25-4ubuntu0.1 |
| devel | released | 0.25-4ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [0.23-1ubuntu2.2]] |
| esm-infra/bionic | released | 0.25-3.1ubuntu0.18.04.2 |
| esm-infra/xenial | released | 0.25-2.1ubuntu16.04.3 |
| precise/esm | DNE | |
| trusty | released | 0.23-1ubuntu2.2 |
| trusty/esm | DNE | trusty was released [0.23-1ubuntu2.2] |
Показывать по
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
There is a reachable assertion in the Internal::TiffReader::visitDirec ...
There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
Уязвимость функции Internal::TiffReader::visitDirectory в tiffvisitor.cpp библиотеки для управления метаданными медиафайлов Exiv2, связанная с недостатком использования функции assert(), позволяющая нарушителю вызвать отказ в обслуживании
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3