Hide Forgot
An issue was discovered in Exiv2 0.26. The readMetadata function in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call. References: https://github.com/Exiv2/exiv2/issues/303
Created exiv2 tracking bugs for this issue: Affects: fedora-all [bug 1579486]
In RHEL 7, the PoC triggered a SIGABRT. Thus, this bug may have some deny of service effect (although not confirmed by upstream so far).
The SIGABRT happens just because the exiv2 app is not catching an intended throwed exception.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:2101 https://access.redhat.com/errata/RHSA-2019:2101
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-10998