Severity
8.1HIGHNVD
EPSS
0.2%
top 57.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateMar 19

Description

Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages4 packages

debiandebian/exiv2< exiv2 0.27.2-6 (bookworm)
Debianexiv2/exiv2< 0.27.2-6+3
Ubuntuexiv2/exiv2< 0.27.5-3ubuntu1.1+9
NVDexiv2/exiv20.27.99.0

Also affects: Debian Linux 10.0

🔴Vulnerability Details

5
OSV
exiv2 regression2026-03-19
OSV
exiv2 vulnerabilities2026-03-18
GHSA
GHSA-q7h8-cc9p-3543: Exiv2 02022-05-24
CVEList
CVE-2020-18771: Exiv2 02021-08-23
OSV
CVE-2020-18771: Exiv2 02021-08-23

📋Vendor Advisories

4
Ubuntu
Exiv2 regression2026-03-19
Ubuntu
Exiv2 vulnerabilities2026-03-18
Debian
CVE-2020-18771: exiv2 - Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNot...2020
Red Hat
exiv2: buffer overflow in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp2019-03-25