Red Hat Bugzilla – Bug 1590993
CVE-2018-12264 exiv2: integer overflow in getData function in preview.cpp
Last modified: 2018-06-15 05:30:49 EDT
A flaw was found in Exiv2 0.26. An integer overflow in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.hpp. References: https://github.com/Exiv2/exiv2/issues/366 https://github.com/TeamSeri0us/pocs/blob/master/exiv2/2-out-of-read-Poc Patch: https://github.com/Exiv2/exiv2/commit/341de4500ab993103c215bfb07d43d4a08654ac4
Created exiv2 tracking bugs for this issue: Affects: fedora-all [bug 1590995]