Stack-based buffer overflow in Exiv2 - #VU146334
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled memory allocation in PgfImage::readMetadata() when parsing a crafted PGF file. A remote attacker can supply a malicious file to trigger excessive memory allocation and impact system performance.
User interaction is required to process the crafted file.