Candidate: CVE-2018-9145 PublicDate: 2018-03-30 08:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9145 https://github.com/xiaoqx/pocs/tree/master/exiv2 Description: In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file. Ubuntu-Description: Notes: mdeslaur> couldn't reproduce, probably 0.26 only Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_exiv2: upstream_exiv2: needs-triage precise/esm_exiv2: DNE trusty_exiv2: not-affected (code not present) trusty/esm_exiv2: DNE (trusty was not-affected [code not present]) xenial_exiv2: not-affected (code not present) esm-infra/xenial_exiv2: not-affected (code not present) artful_exiv2: not-affected (code not present) bionic_exiv2: not-affected (code not present) devel_exiv2: not-affected (code not present)