Red Hat Bugzilla – Bug 1561217
CVE-2018-8977 exiv2: invalid memory access in Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp
Last modified: 2018-04-30 18:19:07 EDT
A flaw was found in Exiv2 0.26, the Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp allows remote attackers to cause a denial of service (invalid memory access) via a crafted file. References: https://github.com/Exiv2/exiv2/issues/247
Created exiv2 tracking bugs for this issue: Affects: fedora-all [bug 1561214]
This issue does not affect the exiv2 version shipped in Red Hat Enterprise Linux 7.4. However, in Red Hat Enterprise Linux 7.5, exiv2 is rebased to the affected version (0.26).