Memory corruption in Exiv2 - CVE-2017-17723
Published: March 13, 2018 / Updated: March 20, 2018
Vulnerability identifier: #VU10963
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17723
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.
The weakness exists in the Exiv2::Image::byteSwap4 function of image.cpp due to boundary error. A remote attacker can send a specially crafted TIFF image file, trick the victim into opening it and cause the service to crash.
The weakness exists in the Exiv2::Image::byteSwap4 function of image.cpp due to boundary error. A remote attacker can send a specially crafted TIFF image file, trick the victim into opening it and cause the service to crash.
Affected software
Exiv2
Gentoo Linux
Fedora
exiv2
Gentoo Linux
Fedora
exiv2
How to mitigate CVE-2017-17723
Cybersecurity is currently unaware of any solutions addressing the vulnerability.
exiv2 - addressed in versions 0.26-10.fc27, 0.26-10.fc28