Integer Overflow Vulnerability in Exiv2 by the Exiv2 Vendor
CVE-2018-12264

8.8HIGH

Key Information:

Vendor

Exiv2

Status
Vendor
CVE Published:
13 June 2018

What is CVE-2018-12264?

An integer overflow vulnerability exists in Exiv2 0.26 specifically within the LoaderTiff::getData() function in preview.cpp. This flaw can lead to out-of-bounds reads in Exiv2::ValueType::setDataArea within value.hpp, potentially allowing attackers to exploit this weakness to manipulate memory and lead to unintended behavior. Keeping Exiv2 updated is essential to protect against this type of vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.