Remote Denial of Service Vulnerability in Exiv2 by Exiv2 Inc.
CVE-2017-11553

7.5HIGH

Key Information:

Vendor

Exiv2

Status
Vendor
CVE Published:
23 July 2017

What is CVE-2017-11553?

The Exiv2 software has a vulnerability in the extend_alias_table function located in localealias.c, which allows for illegal address access. When exploited with crafted input, this vulnerability can lead to a remote denial of service, potentially disrupting service and impacting users. Organizations using Exiv2 0.26 should implement immediate measures to secure their installations.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.