Heap-based Buffer Overflow in Exiv2 Image Library
CVE-2017-11339

6.5MEDIUM

Key Information:

Vendor

Exiv2

Status
Vendor
CVE Published:
3 October 2022

What is CVE-2017-11339?

The Exiv2 image library suffers from a heap-based buffer overflow vulnerability in the Image::printIFDStructure function. By providing crafted input to this function, an attacker can potentially trigger a remote denial of service attack, disrupting services and compromising application stability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.