PT-2021-6516 · Exiv2+4 · Exiv2+4
Kevinbackhouse
·
Published
2021-08-09
·
Updated
2025-01-10
·
CVE-2021-34335
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Exiv2 versions v0.27.4 and earlier
Description
The issue is related to a lack of division by zero check in the Exiv2 library, which can cause a denial of service when a specially crafted image file is used. An attacker could exploit this to cause a denial of service if they can trick the victim into running Exiv2 on a crafted image file. The bug is triggered when printing the interpreted data, which requires an extra command line option (
-p t or -P t).Recommendations
For Exiv2 versions v0.27.4 and earlier, update to version v0.27.5 to resolve the issue. As a temporary workaround, consider avoiding the use of the
-p t or -P t command line options to minimize the risk of exploitation. Restrict access to crafted image files to prevent potential denial of service attacks.Fix
DoS
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Exiv2
Linuxmint
Red Os
Ubuntu