Heap-based Buffer Overflow in Exiv2 0.26: Remote DoS and Potential Impact

Heap-based Buffer Overflow in Exiv2 0.26: Remote DoS and Potential Impact

CVE-2017-12955 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

There is a heap-based buffer overflow in basicio.cpp of Exiv2 0.26. The vulnerability causes an out-of-bounds write in Exiv2::Image::printIFDStructure(), which may lead to remote denial of service or possibly unspecified other impact.

Learn more about our Web Application Penetration Testing UK.