Exiv2
cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*
- 0.28.7
A vulnerability allowing an uncaught exception to be raised has been identified in Exiv2 version 0.28.7. This issue arises from an integer overflow in the preview component, which is triggered when Exiv2 is run with the '-pp' command line argument. The overflow causes the application to attempt creating an excessively large std::vector, leading to a crash. This vulnerability has been patched in version 0.28.8.
Exiv2 crashes due to an uncaught exception caused by the integer overflow, disrupting the application's operation.
The vulnerability can be reproduced by running Exiv2 version 0.28.7 with the '-pp' command line argument. This combination triggers the integer overflow in the preview component, causing the application to crash.
Users can upgrade to Exiv2 version 0.28.8, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.