Bug 1564277 (CVE-2018-9144) - CVE-2018-9144 exiv2: out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp
Summary: CVE-2018-9144 exiv2: out-of-bounds read in Exiv2::Internal::binaryToString in...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2018-9144
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1564278 1564279 1564285
Blocks: 1564287
TreeView+ depends on / blocked
 
Reported: 2018-04-05 21:35 UTC by Laura Pardo
Modified: 2019-09-29 14:35 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
An out-of-bound read has been found in Exiv2 in the way binary bytes are converted to string. An attacker could potentially use this flaw to crash the Exiv2 CLI utility program by tricking it into processing a crafted TIFF image.
Clone Of:
Environment:
Last Closed: 2018-04-17 09:22:37 UTC


Attachments (Terms of Use)

Description Laura Pardo 2018-04-05 21:35:54 UTC
A flaw was found in Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp. This could result in a denial of service or information disclosure. 


References:
https://github.com/Exiv2/exiv2/issues/254
https://bugzilla.novell.com/show_bug.cgi?id=1087877

Comment 1 Laura Pardo 2018-04-05 21:36:22 UTC
Created exiv2 tracking bugs for this issue:

Affects: fedora-all [bug 1564279]

Comment 4 Riccardo Schirone 2018-04-17 09:21:42 UTC
Statement:

This issue did not affect the versions of Exiv2 as shipped with Red Hat Enterprise Linux 6 and 7.


Note You need to log in before you can comment on or make changes to this bug.