PT-2021-4584 · Exiv2+8 · Exiv2+8

Henices

+1

·

Published

2021-04-08

·

Updated

2025-01-10

·

CVE-2021-31292

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 version 0.27.3
Description The issue is related to an integer overflow in the CrwMap::encode0x1810 function of Exiv2, which can be exploited by attackers to trigger a heap-based buffer overflow, causing a denial of service (DOS) via crafted metadata. This can be achieved by remotely exploiting the vulnerability with specially designed metadata.
Recommendations For Exiv2 version 0.27.3, consider disabling the CrwMap::encode0x1810 function as a temporary workaround until a patch is available. Restrict access to crafted metadata to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Integer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2021:4173
ALSA-2021:4319
ALT-PU-2021-2006
ALT-PU-2021-3308
BDU:2021-05262
CESA-2021_4173
CESA-2021_4319
CVE-2021-31292
DLA-2750-1
DSA-4958-1
OESA-2021-1451
OESA-2022-1955
OESA-2022-2044
OPENSUSE-SU-2022_3598-1
PYSEC-2021-877
RHSA-2021:4173
RHSA-2021:4319
RHSA-2021_4173
RHSA-2021_4319
RLSA-2021:4173
RLSA-2021:4319
SUSE-SU-2022:3598-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Exiv2
Red Hat
Red Os
Rocky Linux
Suse