Exiv2 Multiple Remote Denial of Service Vulnerabilities
BID:109279
Info
Exiv2 Multiple Remote Denial of Service Vulnerabilities
| Bugtraq ID: | 109279 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2019-13110 CVE-2019-13112 CVE-2019-13113 CVE-2019-13114 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2019 12:00AM |
| Updated: | Jun 30 2019 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Ubuntu Ubuntu Linux 19.04 Ubuntu Ubuntu Linux 18.10 Ubuntu Ubuntu Linux 18.04 LTS Ubuntu Ubuntu Linux 16.04 LTS Redhat Enterprise Linux 8 Redhat Enterprise Linux 7 Exiv2 Exiv2 0.27.1 Exiv2 Exiv2 0.27 Exiv2 Exiv2 0.26 Exiv2 Exiv2 0.24 |
| Not Vulnerable: | |
Discussion
Exiv2 Multiple Remote Denial of Service Vulnerabilities
Exiv2 is prone to multiple remote denial-of-service vulnerabilities.
An attacker can exploit these issues to cause a denial-of-service condition, denying service to legitimate users.
Exiv2 0.27.1 and prior versions are vulnerable.
Exiv2 is prone to multiple remote denial-of-service vulnerabilities.
An attacker can exploit these issues to cause a denial-of-service condition, denying service to legitimate users.
Exiv2 0.27.1 and prior versions are vulnerable.
Exploit / POC
Exiv2 Multiple Remote Denial of Service Vulnerabilities
The researcher has created a proof-of-concept to demonstrate these issues. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate these issues. Please see the references for more information.
Solution / Fix
Exiv2 Multiple Remote Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Exiv2 Multiple Remote Denial of Service Vulnerabilities
References:
References:
- Bug 1728486 (CVE-2019-13110) - CVE-2019-13110 exiv2: integer-overflow and out-of (Red Hat Bugzilla)
- Bug 1728490 (CVE-2019-13112) - CVE-2019-13112 exiv2: uncontrolled memory allocat (Redhat)
- Bug 1728492 (CVE-2019-13113) - CVE-2019-13113 exiv2: invalid data location in CR (Red Hat Bugzilla)
- Bug 1728494 (CVE-2019-13114) - CVE-2019-13114 exiv2: null-pointer dereference in (Red Hat Bugzilla)
- CVE-2019-13112 (Red Hat Bugzilla)
- CVE-2019-13113 (Red Hat Bugzilla)
- CVE-2019-13114 (Red Hat Bugzilla)
- Exiv2 Homepage (exiv2)
- Integer overflow causes out-of-bounds read in CiffDirectory::readDirectory() (Exiv2)
- Invalid data location in CRW image causes exiv2 to crash (Exiv2)
- null pointer dereference in http.cpp (Exiv2)
- Out of memory error due to unchecked allocation size in PngChunk::parseChunkCont (Exiv2)
- CVE-2019-13110 (Red Hat Bugzilla)
- USN-4056-1: Exiv2 vulnerabilities (Ubuntu)