CVE-2017-14864 PUBLISHED

An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

EPSS 0.12% · 30.4th percentile

Risk Scores

EPSS Score
0.12%
30.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSexiv20, 0.23-1ubuntu1, 0.23-1ubuntu2
Ubuntu:18.04:LTSexiv20.25-3.1ubuntu0.18.04.1, 0, 0.25-3.1
Ubuntu:16.04:LTSexiv20.25-2.1ubuntu16.04.1, 0.25-2.1ubuntu16.04.2, 0

Timeline

References

Open in Interactive Console →