VulnerabilityModified
CVE-2018-9145
In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size.
MEDIUM 6.5EPSS 1.82%
Does this matter?
Lower severity and a low EPSS score (1.82%). Track it; it rarely justifies an emergency change on its own.
Description
In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 1.82% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- exiv2/exiv2
- Source
- cve@mitre.org
References
- https://bugzilla.novell.com/show_bug.cgi?id=1087879Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1564281Issue Tracking, Third Party Advisory
- https://github.com/xiaoqx/pocs/tree/master/exiv2Exploit, Third Party Advisory
- https://security.gentoo.org/glsa/201811-14Third Party Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=1087879Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1564281Issue Tracking, Third Party Advisory
- https://github.com/xiaoqx/pocs/tree/master/exiv2Exploit, Third Party Advisory
- https://security.gentoo.org/glsa/201811-14Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.