Uncontrolled Recursion in libexif - CVE-2018-20030
Published: June 17, 2020
Vulnerability identifier: #VU29107
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20030
CWE-ID: CWE-674
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to recursion issue when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif. A remote attacker can pass specially crafted data to the application and exhaust all available CPU resources.
Affected software
libexif
libexif (Alpine package)
libexif
Slackware Linux
Opensuse
Fedora
libexif (Alpine package)
libexif
Slackware Linux
Opensuse
Fedora
How to mitigate CVE-2018-20030
Install updates from vendor's website.
libexif - update to 0.6.22
libexif (Alpine package) - update to 0.6.22-r0
libexif - addressed in versions 0.6.21-19.fc28, 0.6.21-19.fc29
libexif (Alpine package) - update to 0.6.22-r0
libexif - addressed in versions 0.6.21-19.fc28, 0.6.21-19.fc29