CVE-2019-14982Integer Overflow or Wraparound in Exiv2

Severity
6.5MEDIUMNVD
EPSS
0.6%
top 30.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateMay 24

Description

In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can lead to a buffer overflow vulnerability and a crash.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDexiv2/exiv2< 0.27.2
debiandebian/exiv2

Patches

🔴Vulnerability Details

1
GHSA
GHSA-42mc-7w38-vjxg: In Exiv2 before v02022-05-24

📋Vendor Advisories

2
Red Hat
exiv2: integer overflow in the WebPImage::getHeaderOffset can lead to a out of bounds read2019-07-14
Debian
CVE-2019-14982: exiv2 - In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPI...2019

💬Community

2
Bugzilla
CVE-2019-14982 exiv2: integer overflow in the WebPImage::getHeaderOffset can lead to a out of bounds read [fedora-all]2019-11-22
Bugzilla
CVE-2019-14982 exiv2: integer overflow in the WebPImage::getHeaderOffset can lead to a out of bounds read2019-10-02