Denial of Service Vulnerability in Exiv2 by Exiv2 Team
CVE-2020-18773
6.5MEDIUM
What is CVE-2020-18773?
The vulnerability arises from an invalid memory access in the decode function found in the iptc.cpp file of Exiv2 0.27.99.0. Attackers can exploit this issue by sending a specially crafted TIFF file, which leads to a denial of service condition. Users and administrators running affected versions are at risk, and timely updates should be prioritized to mitigate this security flaw.