PT-2021-7923 · Exiv2+11 · Exiv2+11

Kevinbackhouse

·

Published

2021-05-17

·

Updated

2025-01-10

·

CVE-2021-32617

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 versions v0.27.3 and earlier
Description The issue is related to an inefficient algorithm with quadratic complexity in Exiv2, which can be triggered when writing metadata into a crafted image file. This could potentially allow an attacker to cause a denial of service if they can trick the victim into running Exiv2 on a crafted image file. The bug is only triggered when writing metadata, a less frequently used operation than reading metadata.
Recommendations For Exiv2 versions v0.27.3 and earlier, update to version v0.27.4 to resolve the issue. As a temporary workaround, consider avoiding the use of Exiv2 for writing metadata into image files until the update is applied.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4173
ALT-PU-2021-2006
ALT-PU-2024-13399
AZL-7213
BDU:2023-05484
CESA-2021_4173
CVE-2021-32617
GHSA-W8MV-G8QQ-36MJ
MGASA-2021-0240
OESA-2021-1204
OPENSUSE-SU-2022_3598-1
OPENSUSE-SU-2022_3889-1
OPENSUSE-SU-2024:12381-1
RHSA-2021:4173
RHSA-2021_4173
RLSA-2021:4173
SUSE-SU-2022:3543-1
SUSE-SU-2022:3598-1
SUSE-SU-2022:3889-1
USN-4964-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Exiv2
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu