PT-2022-16763 · Unknown+1 · Metadata-Extractor+1
Huang Wenjie
+2
·
Published
2022-02-24
·
Updated
2025-09-12
·
CVE-2022-24614
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
metadata-extractor versions up to 2.16.0
Description
The issue allows an attacker to cause a denial of service by allocating large amounts of memory when reading a specially crafted JPEG file, potentially affecting services that use the metadata-extractor library. This can lead to an out-of-memory error even with very small inputs.
Recommendations
For metadata-extractor versions up to 2.16.0, update to a version later than 2.16.0 to resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Metadata-Extractor