PT-2021-6516 · Exiv2+4 · Exiv2+4

Kevinbackhouse

·

Published

2021-08-09

·

Updated

2025-01-10

·

CVE-2021-34335

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Exiv2 versions v0.27.4 and earlier
Description The issue is related to a lack of division by zero check in the Exiv2 library, which can cause a denial of service when a specially crafted image file is used. An attacker could exploit this to cause a denial of service if they can trick the victim into running Exiv2 on a crafted image file. The bug is triggered when printing the interpreted data, which requires an extra command line option (-p t or -P t).
Recommendations For Exiv2 versions v0.27.4 and earlier, update to version v0.27.5 to resolve the issue. As a temporary workaround, consider avoiding the use of the -p t or -P t command line options to minimize the risk of exploitation. Restrict access to crafted image files to prevent potential denial of service attacks.

Fix

DoS

Divide By Zero

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3110
ALT-PU-2021-3499
ALT-PU-2024-13399
AZL-7216
BDU:2022-01776
CVE-2021-34335
GHSA-PVJP-M4F6-Q984
MGASA-2021-0415
OESA-2021-1451
OESA-2022-1955
OESA-2022-2044
OPENSUSE-SU-2024:12507-1
USN-5043-1

Affected Products

Alt Linux
Exiv2
Linuxmint
Red Os
Ubuntu