Stack-based buffer overflow in Exiv2 - #VU146334

 

Stack-based buffer overflow in Exiv2 - #VU146334

Published: August 31, 2026


Vulnerability identifier: #VU146334
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled memory allocation in PgfImage::readMetadata() when parsing a crafted PGF file. A remote attacker can supply a malicious file to trigger excessive memory allocation and impact system performance.

User interaction is required to process the crafted file.


Affected software

Exiv2

Remediation

Install security update from vendor's website.

Exiv2 - update to 0.28.9

External References

Related Security Bulletins