Candidate: CVE-2018-9144 PublicDate: 2018-03-30 08:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9144 https://github.com/xiaoqx/pocs/tree/master/exiv2 Description: In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp. It could result in denial of service or information disclosure. Ubuntu-Description: Notes: Bugs: https://github.com/Exiv2/exiv2/issues/254 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H [8.1 HIGH] Patches_exiv2: upstream: https://github.com/Exiv2/exiv2/pull/180 upstream_exiv2: needs-triage precise/esm_exiv2: DNE trusty_exiv2: not-affected (code not present) trusty/esm_exiv2: DNE (trusty was not-affected [code not present]) xenial_exiv2: not-affected (code not present) esm-infra/xenial_exiv2: not-affected (code not present) artful_exiv2: not-affected (code not present) bionic_exiv2: not-affected (code not present) devel_exiv2: not-affected (code not present)