Out-of-bounds read in Exiv2 - CVE-2024-39695
Published: July 8, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in the parser for the ASF video format in AsfVideo::streamProperties(). A remote attacker can pass a specially crafted media file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
openEuler
exiv2
exiv2-debuginfo
exiv2-debugsource
exiv2-devel
exiv2-help
media-gfx/exiv2
How to mitigate CVE-2024-39695
exiv2 - update to 0.28.2-2
exiv2-debuginfo - update to 0.28.2-2
exiv2-debugsource - update to 0.28.2-2
exiv2-devel - update to 0.28.2-2
exiv2-help - update to 0.28.2-2
media-gfx/exiv2 - update to 0.28.8