PT-2021-7699 · Exiv2+6 · Exiv2+6

Kevin Backhouse

·

Published

2021-07-14

·

Updated

2025-01-10

·

CVE-2021-37621

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Exiv2 versions v0.27.4 and earlier
Description The issue is related to an infinite loop in the Exiv2 library, which can be triggered when printing the metadata of a specially crafted image file, potentially allowing a remote attacker to cause a denial of service. This bug is specifically triggered when printing the image ICC profile, a less frequently used operation that requires the extra command line option -p C.
Recommendations For Exiv2 versions v0.27.4 and earlier, update to version v0.27.5 to resolve the issue. As a temporary workaround, consider avoiding the use of the -p C command line option to minimize the risk of exploitation. Restrict access to crafted image files to prevent potential denial of service attacks.

Fix

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3110
ALT-PU-2021-3499
ALT-PU-2024-13399
AZL-7223
BDU:2023-01673
CVE-2021-37621
DLA-3265-1
GHSA-M479-7FRC-GQQG
MGASA-2021-0415
OESA-2021-1451
OESA-2022-1955
OESA-2022-2044
OPENSUSE-SU-2022_3598-1
OPENSUSE-SU-2022_3889-1
OPENSUSE-SU-2024:12381-1
SUSE-SU-2022:3598-1
SUSE-SU-2022:3889-1
USN-5043-1

Affected Products

Alt Linux
Astra Linux
Exiv2
Linuxmint
Red Os
Suse
Ubuntu