Exiv2 Multiple Remote Denial of Service Vulnerabilities
BID:109292
Info
Exiv2 Multiple Remote Denial of Service Vulnerabilities
| Bugtraq ID: | 109292 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-19107 CVE-2018-19108 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 11 2018 12:00AM |
| Updated: | Aug 11 2018 12:00AM |
| Credit: | HongxuChen |
| Vulnerable: |
Ubuntu Ubuntu Linux 19.04 Ubuntu Ubuntu Linux 18.10 Ubuntu Ubuntu Linux 18.04 LTS Ubuntu Ubuntu Linux 16.04 LTS Redhat Enterprise Linux 6 Exiv2 Exiv2 0.26 |
| Not Vulnerable: | |
Discussion
Exiv2 Multiple Remote Denial of Service Vulnerabilities
Exiv2 is prone to multiple remote denial-of-service vulnerabilities.
An attacker can exploit these issues to cause a denial-of-service condition.
Exiv2 0.26 and prior versions are vulnerable.
Exiv2 is prone to multiple remote denial-of-service vulnerabilities.
An attacker can exploit these issues to cause a denial-of-service condition.
Exiv2 0.26 and prior versions are vulnerable.
Exploit / POC
Exiv2 Multiple Remote Denial of Service Vulnerabilities
The researcher has created a proof-of-concept to demonstrate these issues. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate these issues. Please see the references for more information.
Solution / Fix
Exiv2 Multiple Remote Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Exiv2 Multiple Remote Denial of Service Vulnerabilities
References:
References:
- Exiv2 Homepage (exiv2)
- CVE-2018-19108 exiv2: infinite loop in Exiv2::PsdImage::readMetadata in psdimag (Red Hat Bugzilla)
- Fix infinite loop in PsdImage::readMetadata #518 (Github)
- AddressSanitizer: heap-buffer-overflow at iptc.cpp:464 #427 (Github)
- CVE-2018-19107 (Red Hat)
- CVE-2018-19107 exiv2: heap-based buffer over-read in Exiv2::IptcParser::decode i (Red Hat Bugzilla)
- CVE-2018-19108 (Red Hat)
- Infinite loop inside Exiv2::PsdImage::readMetadata (psdimage.cpp) #426 (GitLab)
- USN-4056-1: Exiv2 vulnerabilities (Ubuntu)