CVE-2019-17402

Name
CVE-2019-17402
Description
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://github.com/Exiv2/exiv2/issues/1019
UBUNTU https://usn.ubuntu.com/4159-1/
MLIST https://lists.debian.org/debian-lts-announce/2019/12/msg00001.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:exiv2:exiv2:0.27.2:*:*:*:*:*:*:* exiv2 == None == 0.27.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
exiv2 3.10-main 0.26-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
exiv2 3.11-main 0.27.2-r3 Natanael Copa <ncopa@alpinelinux.org> fixed