CVE-2020-18771

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-18771

OS impact

OSVersionStatusFixed in
arch archfixed0.27.1-1
debian debianbookwormfixed0.27.2-6
debian debianbullseyefixed0.27.2-6
debian debianforkyfixed0.27.2-6
debian debiansidfixed0.27.2-6
debian debiantrixiefixed0.27.2-6

References

Verify integrity in audit chain (admin only). AS-IS.