CVE-2018-19108
Published: 08 November 2018
In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.
Priority
CVSS 3 base score: 6.5
Status
Package | Release | Status |
---|---|---|
exiv2 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(0.25-3.1ubuntu0.18.04.3)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(0.25-2.1ubuntu16.04.4)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
(trusty was needed)
|
|
Patches: Upstream: https://github.com/Exiv2/exiv2/commit/68966932510213b5656fcf433ab6d7e26f48e23b Upstream: https://github.com/Exiv2/exiv2/commit/b7c71f3ad0386cd7af3b73443c0615ada073f0d5 |
Notes
Author | Note |
---|---|
mdeslaur | infinite loop |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19108
- https://github.com/Exiv2/exiv2/pull/518
- https://usn.ubuntu.com/usn/usn-4056-1
- NVD
- Launchpad
- Debian