CVE-2020-18771
published 2021-08-23CVE-2020-18771: Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
PriorityP337high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
1.85%
76.7th percentile
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | exiv2 | < exiv2 0.27.2-6 (bookworm) | exiv2 0.27.2-6 (bookworm) |
| exiv2 | exiv2 | — | — |
| exiv2 | exiv2 | >= 0 < 0.27.2-6 | 0.27.2-6 |
| exiv2 | exiv2 | >= 0 < 0.27.2-6 | 0.27.2-6 |
| exiv2 | exiv2 | >= 0 < 0.27.2-6 | 0.27.2-6 |
| exiv2 | exiv2 | >= 0 < 0.27.2-6 | 0.27.2-6 |
| exiv2 | exiv2 | >= 0 < 0.27.5-3ubuntu1.1 | 0.27.5-3ubuntu1.1 |
| exiv2 | exiv2 | >= 0 < 0.27.5-3ubuntu1.3 | 0.27.5-3ubuntu1.3 |
| exiv2 | exiv2 | >= 0 < 0.27.6-1ubuntu0.1 | 0.27.6-1ubuntu0.1 |
| exiv2 | exiv2 | >= 0 < 0.27.6-1ubuntu0.3 | 0.27.6-1ubuntu0.3 |
| exiv2 | exiv2 | >= 0 < 0.28.5+dfsg-1ubuntu0.1 | 0.28.5+dfsg-1ubuntu0.1 |
| exiv2 | exiv2 | >= 0 < 0.28.5+dfsg-1ubuntu0.3 | 0.28.5+dfsg-1ubuntu0.3 |
| exiv2 | exiv2 | >= 0 < 0.25-2.1ubuntu16.04.7+esm5 | 0.25-2.1ubuntu16.04.7+esm5 |
| exiv2 | exiv2 | >= 0 < 0.25-3.1ubuntu0.18.04.11+esm1 | 0.25-3.1ubuntu0.18.04.11+esm1 |
| exiv2 | exiv2 | >= 0 < 0.27.2-8ubuntu2.7+esm1 | 0.27.2-8ubuntu2.7+esm1 |
| exiv2 | exiv2 | >= 0 < 0.27.2-8ubuntu2.7+esm3 | 0.27.2-8ubuntu2.7+esm3 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Exiv2 regression
vendor_ubuntu·2026-03-19·CVSS 8.1
CVE-2025-55304 [HIGH] Exiv2 regression
Title: Exiv2 regression
Summary: USN-8103-1 introduced a regression in Exiv2
USN-8103-1 fixed vulnerabilities in Exiv2. The update caused a regression
for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and
Ubuntu 25.10. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Exiv2 did not correctly handle reading certain
buffers. An attacker could possibly use this issue to leak sensitive
information. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04
LTS. (CVE-2020-18771)
Wen Cheng discovered that Exiv2 did not correctly handle certain memory
allocation. If a user or system were tricked into opening a specially
crafted file, an attacker could possibly use this issue to cause a denial
of service. This issue on
Ubuntu
Exiv2 vulnerabilities
vendor_ubuntu·2026-03-18·CVSS 8.1
CVE-2026-27631 [HIGH] Exiv2 vulnerabilities
Title: Exiv2 vulnerabilities
Summary: Several security issues were fixed in Exiv2.
It was discovered that Exiv2 did not correctly handle reading certain
buffers. An attacker could possibly use this issue to leak sensitive
information. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04
LTS. (CVE-2020-18771)
Wen Cheng discovered that Exiv2 did not correctly handle certain memory
allocation. If a user or system were tricked into opening a specially
crafted file, an attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2020-18899)
It was discovered that Exiv2 did not correctly handle writing certain
metadata. If a user or system were tricked into opening a specially crafted
file, an attacker could p
Debian
CVE-2020-18771: exiv2 - Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNot...
vendor_debian·2020·CVSS 8.1
CVE-2020-18771 [HIGH] CVE-2020-18771: exiv2 - Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNot...
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: resolved (fixed in 0.27.2-6)
Red Hat
exiv2: buffer overflow in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp
vendor_redhat·2019-03-25·CVSS 8.1
CVE-2020-18771 [HIGH] CWE-119 exiv2: buffer overflow in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp
exiv2: buffer overflow in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
Statement: Red Hat Product Security has determined the Impact to this bug as low for the following reasons:
- The attacker needs access to the system to trigger the bug as exiv2 is a library accompanied by a command line utility.
- While it is possible to crash exiv2 with a malicious payload, there is no known exploit to be able to run arbitrary code or escalate privileges. This only creates an availability problem.
- The bug does not affect any other resources in terms of integrity, confidentiality or avialability.
Package: exiv2 (Red Hat Enter
OSV
exiv2 regression
osv·2026-03-19·CVSS 8.1
CVE-2020-18771 [HIGH] exiv2 regression
exiv2 regression
USN-8103-1 fixed vulnerabilities in Exiv2. The update caused a regression
for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and
Ubuntu 25.10. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Exiv2 did not correctly handle reading certain
buffers. An attacker could possibly use this issue to leak sensitive
information. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04
LTS. (CVE-2020-18771)
Wen Cheng discovered that Exiv2 did not correctly handle certain memory
allocation. If a user or system were tricked into opening a specially
crafted file, an attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2020-
OSV
exiv2 vulnerabilities
osv·2026-03-18·CVSS 8.1
CVE-2020-18771 [HIGH] exiv2 vulnerabilities
exiv2 vulnerabilities
It was discovered that Exiv2 did not correctly handle reading certain
buffers. An attacker could possibly use this issue to leak sensitive
information. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04
LTS. (CVE-2020-18771)
Wen Cheng discovered that Exiv2 did not correctly handle certain memory
allocation. If a user or system were tricked into opening a specially
crafted file, an attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2020-18899)
It was discovered that Exiv2 did not correctly handle writing certain
metadata. If a user or system were tricked into opening a specially crafted
file, an attacker could possibly use this issue to cause a denial of
service. (CVE-2025
GHSA
GHSA-q7h8-cc9p-3543: Exiv2 0
ghsa_unreviewed·2022-05-24
CVE-2020-18771 [HIGH] CWE-125 GHSA-q7h8-cc9p-3543: Exiv2 0
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
OSV
CVE-2020-18771: Exiv2 0
osv·2021-08-23·CVSS 8.1
CVE-2020-18771 [HIGH] CVE-2020-18771: Exiv2 0
Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cwe.mitre.org/data/definitions/126.htmlhttps://github.com/Exiv2/exiv2/issues/756https://lists.debian.org/debian-lts-announce/2023/01/msg00004.htmlhttps://security.gentoo.org/glsa/202312-06https://cwe.mitre.org/data/definitions/126.htmlhttps://github.com/Exiv2/exiv2/issues/756https://lists.debian.org/debian-lts-announce/2023/01/msg00004.htmlhttps://security.gentoo.org/glsa/202312-06
2021-08-23
Published