Float Point Exception in Exiv2 Leading to Denial of Service
CVE-2020-18774

6.5MEDIUM

Key Information:

Vendor

Exiv2

Status
Vendor
CVE Published:
23 August 2021

What is CVE-2020-18774?

A vulnerability exists in Exiv2 that allows attackers to exploit a float point exception within the printLong function found in tags_int.cpp. This vulnerability can be triggered by supplying a specially crafted TIFF file, potentially causing a denial of service. The affected version is Exiv2 0.27.99.0. Users are advised to update their software to mitigate the risk of this vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.