PT-2024-20592 · Exiv2+2 · Exiv2+2

Published

2024-02-12

·

Updated

2026-03-23

·

CVE-2024-24826

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Exiv2 versions v0.28.0 through v0.28.1
Description Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in the QuickTimeVideo::NikonTagsDecoder function, which is triggered when Exiv2 is used to read the metadata of a crafted video file. In most cases, this out-of-bounds read will result in a crash.
Recommendations For Exiv2 versions v0.28.0 through v0.28.1, upgrade to version v0.28.2 to fix the bug. As a temporary workaround, consider avoiding the use of the QuickTimeVideo::NikonTagsDecoder function until a patch is available.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2024-2322
AZL-42500
AZL-42555
CVE-2024-24826
GHSA-G9XM-7538-MQ8W
OPENSUSE-SU-2024:13731-1
OPENSUSE-SU-2026:20410-1
PYSEC-2024-106
SUSE-SU-2026:20923-1

Affected Products

Alt Linux
Debian
Exiv2