Bug 1660424 (CVE-2018-20097) - CVE-2018-20097 exiv2: Segmentation fault in Exiv2::Internal::TiffParserWorker::findPrimaryGroups function
Summary: CVE-2018-20097 exiv2: Segmentation fault in Exiv2::Internal::TiffParserWorker...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-20097
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1660427 1660428 1665494 1665495
Blocks: 1660429
TreeView+ depends on / blocked
 
Reported: 2018-12-18 10:10 UTC by Andrej Nemec
Modified: 2021-02-16 22:38 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2019-08-06 19:20:24 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:2101 0 None None None 2019-08-06 12:14:53 UTC
Red Hat Product Errata RHSA-2020:1577 0 None None None 2020-04-28 15:27:31 UTC

Description Andrej Nemec 2018-12-18 10:10:14 UTC
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack.

Upstream issue:

https://github.com/Exiv2/exiv2/issues/590

References:

https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206

Comment 1 Andrej Nemec 2018-12-18 10:12:57 UTC
Created exiv2 tracking bugs for this issue:

Affects: fedora-all [bug 1660427]


Created mingw-exiv2 tracking bugs for this issue:

Affects: fedora-all [bug 1660428]

Comment 5 Adam Mariš 2019-01-11 15:28:16 UTC
Statement:

This issue did not affect the versions of exiv2 as shipped with Red Hat Enterprise Linux 6. This issue affects the versions of exiv2 as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having a security impact of Low. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Comment 6 errata-xmlrpc 2019-08-06 12:14:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:2101 https://access.redhat.com/errata/RHSA-2019:2101

Comment 7 Product Security DevOps Team 2019-08-06 19:20:24 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2018-20097

Comment 8 errata-xmlrpc 2020-04-28 15:27:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2020:1577 https://access.redhat.com/errata/RHSA-2020:1577


Note You need to log in before you can comment on or make changes to this bug.