CVE-2018-10998
published 2018-05-12CVE-2018-10998: An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect…
PriorityP425medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.47%
82.7th percentile
An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | exiv2 | < exiv2 0.25-4 (bookworm) | exiv2 0.25-4 (bookworm) |
| exiv2 | exiv2 | — | — |
| exiv2 | exiv2 | >= 0 < 0.25-4 | 0.25-4 |
| exiv2 | exiv2 | >= 0 < 0.25-4 | 0.25-4 |
| exiv2 | exiv2 | >= 0 < 0.25-4 | 0.25-4 |
| exiv2 | exiv2 | >= 0 < 0.25-4 | 0.25-4 |
| exiv2 | exiv2 | >= 0 < 0.23-1ubuntu2.1 | 0.23-1ubuntu2.1 |
| exiv2 | exiv2 | >= 0 < 0.25-2.1ubuntu16.04.2 | 0.25-2.1ubuntu16.04.2 |
| exiv2 | exiv2 | >= 0 < 0.25-3.1ubuntu0.18.04.1 | 0.25-3.1ubuntu0.18.04.1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Exiv2 vulnerabilities
vendor_ubuntu·2018-07-03·CVSS 6.5
CVE-2018-10958 [MEDIUM] Exiv2 vulnerabilities
Title: Exiv2 vulnerabilities
Summary: Several security issues were fixed in Exiv2.
It was discovered that Exiv2 incorrectly handled certain files.
An attacker could possibly use this to cause a denial of service.
(CVE-2018-10958, CVE-2018-10998)
It was discovered that Exiv2 incorrectly handled certain PNG files.
An attacker could possibly use this to access sensitive information.
(CVE-2018-10999)
It was discovered that Exiv2 incorrectly handled certain files.
An attacker could possibly use this to execute arbitrary code.
(CVE-2018-11531)
It was discovered that Exiv2 incorrectly handled certain files.
An attacker could possibly use this to access sensitive information.
(CVE-2018-12264, CVE-2018-12265)
Instructions: In general, a standard system update will make all the necessary chang
Red Hat
exiv2: SIGABRT by triggering an incorrect Safe::add call
vendor_redhat·2018-05-09·CVSS 6.5
CVE-2018-10998 [MEDIUM] CWE-400 exiv2: SIGABRT by triggering an incorrect Safe::add call
exiv2: SIGABRT by triggering an incorrect Safe::add call
An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
Package: exiv2 (Red Hat Enterprise Linux 6) - Not affected
Package: exiv2 (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-10998: exiv2 - An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remot...
vendor_debian·2018·CVSS 6.5
CVE-2018-10998 [MEDIUM] CVE-2018-10998: exiv2 - An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remot...
An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
Scope: local
bookworm: resolved (fixed in 0.25-4)
bullseye: resolved (fixed in 0.25-4)
forky: resolved (fixed in 0.25-4)
sid: resolved (fixed in 0.25-4)
trixie: resolved (fixed in 0.25-4)
GHSA
GHSA-gpv8-gxcp-m9x5: An issue was discovered in Exiv2 0
ghsa_unreviewed·2022-05-13
CVE-2018-10998 [MEDIUM] GHSA-gpv8-gxcp-m9x5: An issue was discovered in Exiv2 0
An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
OSV
exiv2 vulnerabilities
osv·2018-07-03·CVSS 6.5
CVE-2018-10958 [MEDIUM] exiv2 vulnerabilities
exiv2 vulnerabilities
It was discovered that Exiv2 incorrectly handled certain files.
An attacker could possibly use this to cause a denial of service.
(CVE-2018-10958, CVE-2018-10998)
It was discovered that Exiv2 incorrectly handled certain PNG files.
An attacker could possibly use this to access sensitive information.
(CVE-2018-10999)
It was discovered that Exiv2 incorrectly handled certain files.
An attacker could possibly use this to execute arbitrary code.
(CVE-2018-11531)
It was discovered that Exiv2 incorrectly handled certain files.
An attacker could possibly use this to access sensitive information.
(CVE-2018-12264, CVE-2018-12265)
OSV
CVE-2018-10998: An issue was discovered in Exiv2 0
osv·2018-05-12·CVSS 6.5
CVE-2018-10998 [MEDIUM] CVE-2018-10998: An issue was discovered in Exiv2 0
An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10998 exiv2: SIGABRT by triggering an incorrect Safe::add call
bugzilla·2018-05-17·CVSS 6.5
CVE-2018-10998 [MEDIUM] CVE-2018-10998 exiv2: SIGABRT by triggering an incorrect Safe::add call
CVE-2018-10998 exiv2: SIGABRT by triggering an incorrect Safe::add call
An issue was discovered in Exiv2 0.26. The readMetadata function in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
References:
https://github.com/Exiv2/exiv2/issues/303
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1579486]
---
In RHEL 7, the PoC triggered a SIGABRT. Thus, this bug may have some deny of service effect (although not confirmed by upstream so far).
---
The SIGABRT happens just because the exiv2 app is not catching an intended throwed exception.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2101 https://access.redhat.com/errata/RHSA
Bugzilla
CVE-2018-10998 CVE-2018-10999 CVE-2018-11037 exiv2: various flaws [fedora-all]
bugzilla·2018-05-17·CVSS 6.5
CVE-2018-10998 [MEDIUM] CVE-2018-10998 CVE-2018-10999 CVE-2018-11037 exiv2: various flaws [fedora-all]
CVE-2018-10998 CVE-2018-10999 CVE-2018-11037 exiv2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2018-7712 opencv: assertion failure in validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp
bugzilla·2018-03-08·CVSS 7.5
CVE-2018-7712 [HIGH] CVE-2018-7712 opencv: assertion failure in validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp
CVE-2018-7712 opencv: assertion failure in validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp
The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denial of service (assertion failure) because (size.height <= (1<<20)) may be false.
References:
https://github.com/opencv/opencv/issues/10998
https://github.com/xiaoqx/pocs/tree/master/opencv/dos-by-assert
Discussion:
Created opencv tracking bugs for this issue:
Affects: fedora-all [bug 1553468]
Bugzilla
CVE-2018-7714 opencv: assertion failure in validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp
bugzilla·2018-03-08·CVSS 7.5
CVE-2018-7714 [HIGH] CVE-2018-7714 opencv: assertion failure in validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp
CVE-2018-7714 opencv: assertion failure in validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp
The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denial of service (assertion failure) because (pixels <= (1<<30)) may be false.
References:
https://github.com/opencv/opencv/issues/10998
https://github.com/xiaoqx/pocs/tree/master/opencv/dos-by-assert
Discussion:
Created opencv tracking bugs for this issue:
Affects: fedora-all [bug 1553468]
Bugzilla
CVE-2018-7713 opencv: assertion failure in validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp
bugzilla·2018-03-08·CVSS 7.5
CVE-2018-7713 [HIGH] CVE-2018-7713 opencv: assertion failure in validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp
CVE-2018-7713 opencv: assertion failure in validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp
The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denial of service (assertion failure) because (size.width <= (1<<20)) may be false.
References:
https://github.com/opencv/opencv/issues/10998
https://github.com/xiaoqx/pocs/tree/master/opencv/dos-by-assert
Discussion:
Created opencv tracking bugs for this issue:
Affects: fedora-all [bug 1553468]
https://access.redhat.com/errata/RHSA-2019:2101https://github.com/Exiv2/exiv2/issues/303https://lists.debian.org/debian-lts-announce/2018/06/msg00010.htmlhttps://security.gentoo.org/glsa/201811-14https://usn.ubuntu.com/3700-1/https://www.debian.org/security/2018/dsa-4238https://access.redhat.com/errata/RHSA-2019:2101https://github.com/Exiv2/exiv2/issues/303https://lists.debian.org/debian-lts-announce/2018/06/msg00010.htmlhttps://security.gentoo.org/glsa/201811-14https://usn.ubuntu.com/3700-1/https://www.debian.org/security/2018/dsa-4238
2018-05-12
Published