CVE-2020-19716
published 2021-07-13CVE-2020-19716: A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).
PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.14%
63.1th percentile
A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | exiv2 | < exiv2 0.27.2-6 (bookworm) | exiv2 0.27.2-6 (bookworm) |
| exiv2 | exiv2 | — | — |
| exiv2 | exiv2 | >= 0 < 0.27.2-6 | 0.27.2-6 |
| exiv2 | exiv2 | >= 0 < 0.27.2-6 | 0.27.2-6 |
| exiv2 | exiv2 | >= 0 < 0.27.2-6 | 0.27.2-6 |
| exiv2 | exiv2 | >= 0 < 0.27.2-6 | 0.27.2-6 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hhmh-w64h-2vvx: A buffer overflow vulnerability in the Databuf function in types
ghsa_unreviewed·2022-05-24
CVE-2020-19716 [MEDIUM] CWE-120 GHSA-hhmh-w64h-2vvx: A buffer overflow vulnerability in the Databuf function in types
A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).
OSV
CVE-2020-19716: A buffer overflow vulnerability in the Databuf function in types
osv·2021-07-13·CVSS 6.5
CVE-2020-19716 [MEDIUM] CVE-2020-19716: A buffer overflow vulnerability in the Databuf function in types
A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).
Red Hat
exiv2: buffer overflow in Databuf function in types.cpp leads to DoS
vendor_redhat·2021-07-13·CVSS 6.5
CVE-2020-19716 [MEDIUM] CWE-400 exiv2: buffer overflow in Databuf function in types.cpp leads to DoS
exiv2: buffer overflow in Databuf function in types.cpp leads to DoS
A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).
There's a flaw in exiv2. An attacker able to submit a crafted file to an application linked with exiv2 could trigger excessive resource consumption or a null pointer dereference, leading to an impact to application availability.
Statement: This flaw does not affect exiv2 as shipped with Red Hat Enterprise Linux 8; the fix is already applied. This flaw is out of support scope for exiv2 as shipped with Red Hat Enterprise Linux 7, and did not reproduce on it.
Package: exiv2 (Red Hat Enterprise Linux 6) - Out of support scope
Package: exiv2 (Red Hat Enterprise Linux 7) - Out of support scope
Package:
Debian
CVE-2020-19716: exiv2 - A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0...
vendor_debian·2020·CVSS 6.5
CVE-2020-19716 [MEDIUM] CVE-2020-19716: exiv2 - A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0...
A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: resolved (fixed in 0.27.2-6)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-07-13
Published