Junglewise Threat Intelligence

CVE-2018-20096: PYSEC-2018-117 - There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to

CVE-2018-20096 · Severity: low · CVSS 3 · Published 2018-12-12

Technologies: exiv2 (PyPI). Vendors: PyPI.

Executive brief

There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

Affected products

  • PyPI exiv2

Related threats