Integer Overflow Vulnerability in Exiv2 Affects Multiple Linux Distributions
CVE-2018-12265
8.8HIGH
What is CVE-2018-12265?
Exiv2 version 0.26 contains an integer overflow in the LoaderExifJpeg class within preview.cpp, which can result in an out-of-bounds read in the MemIo::read function located in basicio.cpp. This vulnerability may allow attackers to exploit the application, posing risks, especially on systems using this library for managing image metadata.