PT-2021-8245 · Exiv2+9 · Exiv2+9

Kevinbackhouse

·

Published

2021-04-20

·

Updated

2025-01-10

·

CVE-2021-29463

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 versions v0.27.3 and earlier
Description An out-of-bounds read was found in Exiv2 when used to write metadata into a crafted image file. This could potentially be exploited by an attacker to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. The bug is only triggered when writing metadata, which is a less frequently used operation than reading metadata.
Recommendations For Exiv2 versions v0.27.3 and earlier, update to version v0.27.4 to resolve the issue. As a temporary workaround, consider avoiding the use of the insert command-line argument when running the Exiv2 command-line application, to minimize the risk of exploitation.

Fix

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2021:4173
ALT-PU-2021-2006
ALT-PU-2024-13399
AZL-7208
BDU:2025-00361
CESA-2021_4173
CVE-2021-29463
GHSA-5P8G-9XF3-GFRR
MGASA-2021-0240
OESA-2021-1183
OPENSUSE-SU-2022_3889-1
OPENSUSE-SU-2022_3892-1
OPENSUSE-SU-2024:12440-1
RHSA-2021:4173
RHSA-2021_4173
RLSA-2021:4173
SUSE-SU-2022:3889-1
SUSE-SU-2022:3892-1
USN-4964-1

Affected Products

Alt Linux
Almalinux
Centos
Exiv2
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu