Red Hat Bugzilla – Bug 1624977
CVE-2018-16336 exiv2: heap-based buffer over-read via a crafted image file
Last modified: 2018-09-05 01:00:16 EDT
A flaw was found in Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE-2018-10999. References: https://github.com/Exiv2/exiv2/issues/400
Created exiv2 tracking bugs for this issue: Affects: fedora-all [bug 1624978]
Upstream patch: https://github.com/Exiv2/exiv2/commit/35b3e596edacd2437c2c5d3dd2b5c9502626163d