Denial of Service Vulnerability in Exiv2 by Exiv2 Team
CVE-2020-18773

6.5MEDIUM

Key Information:

Vendor

Exiv2

Status
Vendor
CVE Published:
23 August 2021

What is CVE-2020-18773?

The vulnerability arises from an invalid memory access in the decode function found in the iptc.cpp file of Exiv2 0.27.99.0. Attackers can exploit this issue by sending a specially crafted TIFF file, which leads to a denial of service condition. Users and administrators running affected versions are at risk, and timely updates should be prioritized to mitigate this security flaw.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.