CVE-2018-9145

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
30/03/2018
Last modified:
27/03/2019

Description

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:exiv2:exiv2:0.26:*:*:*:*:*:*:*