CVE-2017-14857Use After Free in Exiv2

CWE-416Use After Free6 documents5 sources
Severity
5.5MEDIUMNVD
EPSS
0.3%
top 50.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 29
Latest updateMay 17

Description

In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a Segmentation fault. A crafted input will lead to a denial of service attack.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDexiv2/exiv20.26
debiandebian/exiv2

🔴Vulnerability Details

1
GHSA
GHSA-h836-f2j9-x39j: In Exiv2 02022-05-17

📋Vendor Advisories

2
Red Hat
exiv2: Invalid free in the Image class2017-09-25
Debian
CVE-2017-14857: exiv2 - In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that lea...2017

💬Community

2
Bugzilla
CVE-2017-14857 exiv2: Invalid free in the Image class2017-10-10
Bugzilla
CVE-2017-1000126 CVE-2017-1000127 CVE-2017-1000128 CVE-2017-11553 CVE-2017-11591 CVE-2017-11592 CVE-2017-11683 CVE-2017-12955 CVE-2017-12956 CVE-2017-12957 CVE-2017-14857 CVE-2017-14858 CVE-2017-148592017-07-26