#VU28798 Infinite loop in Exiv2


Published: 2020-06-08 | Updated: 2020-06-30

Vulnerability identifier: #VU28798

Vulnerability risk: Medium

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-20421

CWE-ID: CWE-835

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Exiv2
Universal components / Libraries / Libraries used by multiple products

Vendor: GNU

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the Jp2Image::readMetadata() in jp2image.cpp. A remote attacker can create a specially crafted image file, pass it to the affected application and consume all available system resources or cause denial of service conditions.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Exiv2: 0.16 - 0.27.2


External links
http://github.com/Exiv2/exiv2/commit/a82098f4f90cd86297131b5663c3dec6a34470e8
http://github.com/Exiv2/exiv2/issues/1011
http://usn.ubuntu.com/4270-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability