Bug 1660426 (CVE-2018-20099) - CVE-2018-20099 exiv2: Infinite loop in Exiv2::Jp2Image::encodeJp2Header resulting in a denial of service
Summary: CVE-2018-20099 exiv2: Infinite loop in Exiv2::Jp2Image::encodeJp2Header resul...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-20099
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1660427 1660428 1665498 1665499
Blocks: 1660429
TreeView+ depends on / blocked
 
Reported: 2018-12-18 10:11 UTC by Andrej Nemec
Modified: 2020-04-28 15:27 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-08-06 19:20:27 UTC


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:2101 None None None 2019-08-06 12:14:56 UTC
Red Hat Product Errata RHSA-2020:1577 None None None 2020-04-28 15:27:35 UTC

Description Andrej Nemec 2018-12-18 10:11:57 UTC
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack.

Upstream issue:

https://github.com/Exiv2/exiv2/issues/590

References:

https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206

Comment 1 Andrej Nemec 2018-12-18 10:12:51 UTC
Created exiv2 tracking bugs for this issue:

Affects: fedora-all [bug 1660427]


Created mingw-exiv2 tracking bugs for this issue:

Affects: fedora-all [bug 1660428]

Comment 5 Adam Mariš 2019-01-11 15:28:27 UTC
Statement:

This issue did not affect the versions of exiv2 as shipped with Red Hat Enterprise Linux 6. This issue affects the versions of exiv2 as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having a security impact of Low. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Comment 6 errata-xmlrpc 2019-08-06 12:14:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:2101 https://access.redhat.com/errata/RHSA-2019:2101

Comment 7 Product Security DevOps Team 2019-08-06 19:20:27 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2018-20099

Comment 8 errata-xmlrpc 2020-04-28 15:27:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2020:1577 https://access.redhat.com/errata/RHSA-2020:1577


Note You need to log in before you can comment on or make changes to this bug.