CVE-2018-14338: EXIV2

High severity, CVSS 8.1. EPSS: 1.4% chance of exploitation in the next 30 days.

samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple platforms) where glibc is not used, possibly leading to a buffer overflow.

Affected products

  • EXIV2 EXIV2: version 0.26 only

Published 2018-07-17. Last modified 2026-06-17.