VDB
Sign up
MEDIUM6.5

PYSEC-2019-257

Details

http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/exiv2

No fixed version published yet for exiv2 (pip). Pin to a known-safe version or switch to an alternative.

References