CVE-2018-14338 PUBLISHED CVSS 8.100000381469727 HIGH

samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple platforms) where glibc is not used, possibly leading to a buffer overflow.

EPSS 0.39% · 60.0th percentile

Risk Scores

CVSS v3.0
8.100000381469727
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.39%
60.0th percentile

Affected Products

VendorProductVersions
exiv2exiv20.26
n/an/an/a

Timeline

References

Open in Interactive Console →