Security Advisory

CVE-2018-9145

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-03-30 08:00:00
Last updated 2024-08-05 07:17:51
Assigner mitre
State PUBLISHED

Description

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.