Medium severity6.5NVD Advisory· Published Dec 12, 2018· Updated Jun 17, 2026
CVE-2018-20096
CVE-2018-20096
Description
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- osv-coords6 versionspkg:rpm/almalinux/exiv2-develpkg:rpm/almalinux/exiv2-docpkg:rpm/almalinux/geglpkg:rpm/almalinux/gnome-color-managerpkg:rpm/almalinux/libgexiv2pkg:rpm/almalinux/libgexiv2-devel
< 0.27.2-5.el8+ 5 more
- (no CPE)range: < 0.27.2-5.el8
- (no CPE)range: < 0.27.2-5.el8
- (no CPE)range: < 0.2.0-39.el8
- (no CPE)range: < 3.28.0-3.el8
- (no CPE)range: < 0.10.8-4.el8
- (no CPE)range: < 0.10.8-4.el8
Patches
Vulnerability mechanics
References
4- github.com/Exiv2/exiv2/issues/590nvdExploitIssue TrackingPatchThird Party Advisory
- github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206nvdExploitThird Party Advisory
- access.redhat.com/errata/RHSA-2019:2101nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZXCEKTYF7HLM6VH2WCWO2HXTJH37MBLA/nvd
News mentions
0No linked articles in our index yet.