Vulnerability Name:

CVE-2017-1000126 (CCN-135114)

Assigned:2017-06-30
Published:2017-06-30
Updated:2020-04-09
Summary:exiv2 0.26 contains a Stack out of bounds read in webp parser
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
4.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-125
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2017-1000126

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2020:0482

Source: CCN
Type: Exiv2 Web site
Exiv2

Source: CCN
Type: oss-security Mailing List, Fri, 30 Jun 2017 10:34:34 +0200
exiv2: multiple memory safety issues

Source: MLIST
Type: Mailing List, Third Party Advisory, VDB Entry
[oss-security] 20170630 exiv2: multiple memory safety issues

Source: XF
Type: UNKNOWN
exiv2-cve20171000126-bo(135114)

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2017-1000126

Vulnerable Configuration:Configuration 1:
  • cpe:/a:exiv2:exiv2:0.26:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:exiv2:exiv2:0.26:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20171000126
    V
    CVE-2017-1000126
    2023-06-22
    oval:org.opensuse.security:def:7930
    P
    libexiv2-27-0.27.5-150400.15.4.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:94050
    P
    (Important)
    2022-07-14
    oval:org.opensuse.security:def:3225
    P
    libopus0-1.1-3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3127
    P
    libIlmImf-Imf_2_1-21-2.1.0-6.13.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3186
    P
    libicu-doc-52.1-8.7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3243
    P
    libpython3_6m1_0-3.6.8-2.13 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3167
    P
    libecpg6-10.10-1.15.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3134
    P
    libXcursor1-1.1.14-4.6.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3216
    P
    libneon27-0.30.0-3.64 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3122
    P
    lcms2-2.7-9.7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3237
    P
    libpoppler-glib8-0.43.0-16.15.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3175
    P
    libgcab-1_0-0-0.6-1.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3239
    P
    libproxy1-0.4.13-16.3 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3240
    P
    libpulse-mainloop-glib0-32bit-5.0-4.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3148
    P
    libXv1-1.0.10-7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3310
    P
    openssh-7.2p2-74.45.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94940
    P
    libexiv2-26-0.26-6.8.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2873
    P
    axis-1.4-11.65 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2883
    P
    bzip2-1.0.8-150400.1.122 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:100763
    P
    (Important)
    2022-03-08
    oval:org.opensuse.security:def:1695
    P
    Security update for apache2 (Important)
    2022-01-17
    oval:org.opensuse.security:def:1579
    P
    Security update for python-pip (Moderate)
    2021-12-13
    oval:org.opensuse.security:def:1223
    P
    Security update for the Linux Kernel (Important)
    2021-11-16
    oval:org.opensuse.security:def:64613
    P
    Security update for samba (Important)
    2021-11-10
    oval:org.opensuse.security:def:65254
    P
    Security update for ffmpeg (Moderate)
    2021-10-26
    oval:org.opensuse.security:def:74667
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:69140
    P
    Security update for mariadb (Moderate)
    2021-09-03
    oval:org.opensuse.security:def:64555
    P
    Security update for c-ares (Important)
    2021-08-17
    oval:org.opensuse.security:def:2235
    P
    dovecot23-2.3.11.3-17.5.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2233
    P
    davfs2-1.5.4-3.3.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2228
    P
    apache2-mod_jk-1.2.43-6.3.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63504
    P
    openconnect-7.08-6.9.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63008
    P
    glibc-devel-32bit-2.31-7.20 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62798
    P
    libmms-devel-0.6.4-1.24 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72493
    P
    libXvnc-devel-1.9.0-19.9.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62802
    P
    libnetpbm-devel-10.80.1-3.11.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71838
    P
    gstreamer-plugins-good-1.16.2-1.85 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62830
    P
    spice-vdagent-0.20.0-1.51 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101190
    P
    libexiv2-26-0.26-6.8.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62784
    P
    libexiv2-26-0.26-6.8.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62805
    P
    libout123-0-1.26.4-1.15 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72503
    P
    libexiv2-26-0.26-6.8.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71954
    P
    libserf-1-1-1.3.9-2.31 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:64725
    P
    Security update for the Linux Kernel (Important)
    2021-06-28
    oval:org.opensuse.security:def:48687
    P
    libmysqlclient_r18-10.0.11-6.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48704
    P
    raptor-2.0.10-3.67 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48829
    P
    drm-kmp-default-4.9.33_k4.4.73_5-2.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48686
    P
    libmikmod3-3.2.0-4.59 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:69037
    P
    Security update for qemu (Important)
    2021-04-16
    oval:org.opensuse.security:def:66730
    P
    Security update for zstd (Moderate)
    2021-04-08
    oval:org.opensuse.security:def:69981
    P
    Security update for screen (Important)
    2021-02-17
    oval:org.opensuse.security:def:64453
    P
    Security update for python3 (Important)
    2020-12-23
    oval:org.opensuse.security:def:2194
    P
    libvirglrenderer0-0.6.0-4.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:3894
    P
    gc-devel-7.2d-5.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49030
    P
    libpolkit0-32bit-0.113-5.18.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2176
    P
    grub2-x86_64-xen-2.04-7.9 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2223
    P
    yast2-rmt-1.3.0-1.43 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2169
    P
    dhcp-relay-4.3.5-6.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63301
    P
    salt-api-3000-2.9 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62668
    P
    libexiv2-26-0.26-6.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2197
    P
    libxmltooling-devel-1.6.4-3.3.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116987
    P
    libexiv2-26-0.26-6.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72387
    P
    libexiv2-26-0.26-6.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2184
    P
    libfpm_pb0-1.1.1-2.29 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72377
    P
    libXt6-32bit-1.1.5-2.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107429
    P
    libexiv2-26-0.26-6.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2172
    P
    erlang-rabbitmq-client-3.8.3-1.27 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:3881
    P
    eog-devel-3.20.4-7.7 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2204
    P
    postgresql-contrib-12-2.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:65164
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:64209
    P
    apparmor-abstractions on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73303
    P
    python3-requests on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49267
    P
    libykcs11-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:68601
    P
    Security update for exiv2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49876
    P
    gv on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49787
    P
    kernel-docs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50648
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49610
    P
    PackageKit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49639
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63651
    P
    Security update for qemu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49907
    P
    kernel-azure-base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50815
    P
    Security update for shim (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49744
    P
    libtidy-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:65703
    P
    Security update for php7 (Important)
    2020-12-01
    oval:org.opensuse.security:def:49640
    P
    hplip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50245
    P
    libraw-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50882
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:49664
    P
    libexiv2-26 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64345
    P
    libldb-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51256
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:49422
    P
    libXi6-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50914
    P
    Security update for ruby2.5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:65793
    P
    Security update for exiv2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49994
    P
    bind on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73421
    P
    libexiv2-26 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50741
    P
    Security update for autoyast2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66638
    P
    tboot on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63880
    P
    Security update for openwsman (Important)
    2020-12-01
    oval:org.opensuse.security:def:49980
    P
    spice-gtk-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70086
    P
    libexiv2-26 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49172
    P
    libhogweed4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51318
    P
    Security update for exiv2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74800
    P
    Security update for exiv2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49659
    P
    libcdio++0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52264
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:50404
    P
    Security update for elfutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64346
    P
    libltdl7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:68498
    P
    Security update for taglib (Low)
    2020-12-01
    oval:org.opensuse.security:def:49655
    P
    libXvnc-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50988
    P
    Security update for hunspell (Low)
    2020-12-01
    oval:org.opensuse.security:def:50145
    P
    gegl-0_3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52326
    P
    Security update for exiv2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49811
    P
    xorg-x11-server-sdk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:110462
    P
    Security update for exiv2 (Moderate)
    2020-04-08
    oval:org.opensuse.security:def:90609
    P
    Security update for exiv2 (Moderate)
    2020-04-03
    oval:org.opensuse.security:def:98148
    P
    Security update for exiv2 (Moderate)
    2020-04-03
    oval:org.opensuse.security:def:75544
    P
    Security update for exiv2 (Moderate)
    2020-04-03
    oval:org.opensuse.security:def:104264
    P
    Security update for exiv2 (Moderate)
    2020-04-03
    oval:org.opensuse.security:def:91183
    P
    Security update for exiv2 (Moderate)
    2020-04-03
    oval:org.opensuse.security:def:104838
    P
    Security update for exiv2 (Moderate)
    2020-04-03
    oval:org.opensuse.security:def:97574
    P
    Security update for exiv2 (Moderate)
    2020-04-03
    oval:com.ubuntu.artful:def:20171000126000
    V
    CVE-2017-1000126 on Ubuntu 17.10 (artful) - low.
    2017-11-17
    oval:com.ubuntu.bionic:def:201710001260000000
    V
    CVE-2017-1000126 on Ubuntu 18.04 LTS (bionic) - low.
    2017-11-17
    oval:com.ubuntu.bionic:def:20171000126000
    V
    CVE-2017-1000126 on Ubuntu 18.04 LTS (bionic) - low.
    2017-11-17
    oval:com.ubuntu.xenial:def:201710001260000000
    V
    CVE-2017-1000126 on Ubuntu 16.04 LTS (xenial) - low.
    2017-11-17
    oval:com.ubuntu.trusty:def:20171000126000
    V
    CVE-2017-1000126 on Ubuntu 14.04 LTS (trusty) - low.
    2017-11-17
    oval:com.ubuntu.xenial:def:20171000126000
    V
    CVE-2017-1000126 on Ubuntu 16.04 LTS (xenial) - low.
    2017-11-17
    BACK
    exiv2 exiv2 0.26
    exiv2 exiv2 0.26