CVE-2020-18898

Related Vulnerabilities: CVE-2020-18898  

A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.

Description

The MITRE CVE dictionary describes this issue as:

A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.

Additional Information

  • Bugzilla 2002678: CVE-2020-18898 exiv2: stack exhaustion issue in the printIFDStructure function may lead to DoS
  • CWE-787: Out-of-bounds Write
  • FAQ: Frequently asked questions about CVE-2020-18898