Unrated severityNVD Advisory· Published Dec 12, 2018· Updated Aug 5, 2024
CVE-2018-20096
CVE-2018-20096
Description
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords6 versionspkg:rpm/almalinux/exiv2-develpkg:rpm/almalinux/exiv2-docpkg:rpm/almalinux/geglpkg:rpm/almalinux/gnome-color-managerpkg:rpm/almalinux/libgexiv2pkg:rpm/almalinux/libgexiv2-devel
< 0.27.2-5.el8+ 5 more
- (no CPE)range: < 0.27.2-5.el8
- (no CPE)range: < 0.27.2-5.el8
- (no CPE)range: < 0.2.0-39.el8
- (no CPE)range: < 3.28.0-3.el8
- (no CPE)range: < 0.10.8-4.el8
- (no CPE)range: < 0.10.8-4.el8
Patches
Vulnerability mechanics
References
4- access.redhat.com/errata/RHSA-2019:2101mitrevendor-advisoryx_refsource_REDHAT
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZXCEKTYF7HLM6VH2WCWO2HXTJH37MBLA/mitrevendor-advisoryx_refsource_FEDORA
- github.com/Exiv2/exiv2/issues/590mitrex_refsource_MISC
- github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.