Candidate: CVE-2017-11338 PublicDate: 2017-07-17 13:18:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11338 Description: There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack. Ubuntu-Description: Notes: debian> Vulnerable code introduced after 0.25 Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=868578 https://bugzilla.redhat.com/show_bug.cgi?id=1470913 https://github.com/Exiv2/exiv2/issues/51 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_exiv2: upstream: https://github.com/Exiv2/exiv2/pull/120 upstream_exiv2: needs-triage precise/esm_exiv2: DNE trusty_exiv2: not-affected (code not present) trusty/esm_exiv2: DNE (trusty was not-affected [code not present]) xenial_exiv2: not-affected (code not present) esm-infra/xenial_exiv2: not-affected (code not present) artful_exiv2: not-affected (code not present) bionic_exiv2: not-affected (code not present) devel_exiv2: not-affected (code not present)