A vulnerability was discovered in http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character. Reference: https://github.com/Exiv2/exiv2/issues/793 https://github.com/Exiv2/exiv2/pull/815
Created exiv2 tracking bugs for this issue: Affects: fedora-all [bug 1728495]
Upstream patch: https://github.com/Exiv2/exiv2/commit/ccde30afa8ca787a3fe17388a15977f107a53b72 [master branch] https://github.com/Exiv2/exiv2/commit/ae20c30805b330275b2aa0303a42e1f2bbd53661 [0.27-maintenance branch]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:1577 https://access.redhat.com/errata/RHSA-2020:1577
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-13114