5.8
CVSSv2

CVE-2017-17723

Published: 12/02/2018 Updated: 03/10/2019
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp. Remote attackers can exploit this vulnerability to disclose memory data or cause a denial of service via a crafted TIFF file.

Vulnerable Product Search on Vulmon Subscribe to Product

exiv2 exiv2 0.26

Vendor Advisories

An integer wraparound, leading to heap-based out-of-bound read, was found in the way Exiv2 library prints Image File Directory(IFD) in TIFF images By persuading a victim to open a crafted TIFF image, a remote attacker could crash the application or possibly retrieve a portion of memory ...
In Exiv2 026, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in imagecpp Remote attackers can exploit this vulnerability to disclose memory data or cause a denial of service via a crafted TIFF file ...