CVE-2018-12265Out-of-bounds Read in Exiv2

Severity
8.8HIGHNVD
OSV6.5
EPSS
0.7%
top 27.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 14

Description

Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

debiandebian/exiv2< exiv2 0.25-4 (bookworm)
Debianexiv2/exiv2< 0.25-4+3
Ubuntuexiv2/exiv2< 0.23-1ubuntu2.1+2
NVDexiv2/exiv20.26

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10, 18.04

🔴Vulnerability Details

3
GHSA
GHSA-7xfp-xm3p-9p92: Exiv2 02022-05-14
OSV
exiv2 vulnerabilities2018-07-03
OSV
CVE-2018-12265: Exiv2 02018-06-13

📋Vendor Advisories

3
Ubuntu
Exiv2 vulnerabilities2018-07-03
Red Hat
exiv2: integer overflow in the LoaderExifJpeg class in preview.cpp2018-06-11
Debian
CVE-2018-12265: exiv2 - Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, l...2018

💬Community

2
Bugzilla
CVE-2018-12265 exiv2: integer overflow in the LoaderExifJpeg class in preview.cpp2018-06-13
Bugzilla
CVE-2018-12265 exiv2: integer overflow in the LoaderExifJpeg class in preview.cpp [fedora-all]2018-06-13