Uncontrolled Recursion in libexif - CVE-2018-20030

 

Uncontrolled Recursion in libexif - CVE-2018-20030

Published: June 17, 2020


Vulnerability identifier: #VU29107
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20030
CWE-ID: CWE-674
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to recursion issue when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif. A remote attacker can pass specially crafted data to the application and exhaust all available CPU resources.


Affected software

libexif
libexif (Alpine package)
libexif
Slackware Linux
Opensuse
Fedora

How to mitigate CVE-2018-20030

Install updates from vendor's website.

libexif - update to 0.6.22
libexif (Alpine package) - update to 0.6.22-r0
libexif - addressed in versions 0.6.21-19.fc28, 0.6.21-19.fc29

External References

Related Security Bulletins