5.5
CVSSv3

CVE-2017-18005

Published: 31/12/2017 Updated: 13/01/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a TIFF file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

exiv2 exiv2 0.26

debian debian linux 10.0

Vendor Advisories

Synopsis Moderate: exiv2 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for exiv2, gegl, gnome-color-manager, and libgexiv2 is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moder ...
Debian Bug report logs - #885981 exiv2: CVE-2017-18005: Null Pointer Dereference in the Exiv2::DataValue::toLong function Package: src:exiv2; Maintainer for src:exiv2 is Debian KDE Extras Team <pkg-kde-extras@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 1 Jan 2018 09:42:0 ...
Exiv2 026 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in valuecpp, related to crafted metadata in a TIFF file ...