Red Hat Bugzilla – Bug 1579481
CVE-2018-10998 exiv2: SIGABRT by triggering an incorrect Safe::add call
Last modified: 2018-05-21 06:04:05 EDT
An issue was discovered in Exiv2 0.26. The readMetadata function in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call. References: https://github.com/Exiv2/exiv2/issues/303
Created exiv2 tracking bugs for this issue: Affects: fedora-all [bug 1579486]
In RHEL 7, the PoC triggered a SIGABRT. Thus, this bug may have some deny of service effect (although not confirmed by upstream so far).
The SIGABRT happens just because the exiv2 app is not catching an intended throwed exception.