VDB
Sign up
MEDIUM6.5

PYSEC-2018-117

Details

There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/exiv2
Introduced in: 0

No fixed version published yet for exiv2 (pip). Pin to a known-safe version or switch to an alternative.

References