6.5

CVE-2018-17581

Exploit
CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Exiv2 ≫ Exiv2 Version 0.26
Exiv2 ≫ Exiv2 Version 0.27
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.35% 0.815
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://usn.ubuntu.com/3852-1/
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/01/msg00004.html
Third Party Advisory
Mailing List
https://access.redhat.com/errata/RHSA-2019:2101
Third Party Advisory
https://github.com/Exiv2/exiv2/issues/460
Patch
Third Party Advisory
Exploit
https://github.com/SegfaultMasters/covering360/blob/master/Exiv2
Patch
Third Party Advisory
Exploit
https://lists.debian.org/debian-lts-announce/2019/02/msg00038.html
Third Party Advisory
Mailing List