CVE-2017-11592: EXIV2

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

There is a Mismatched Memory Management Routines vulnerability in the Exiv2::FileIo::seek function of Exiv2 0.26 that will lead to a remote denial of service attack (heap memory corruption) via crafted input.

Affected products

  • EXIV2 EXIV2: version 0.26 only

Published 2017-07-24. Last modified 2026-06-17.