Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-25884

Опубликовано: 02 мар. 2026
Источник: debian
EPSS Низкий

Описание

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found. The vulnerability is in the CRW image parser. This issue has been patched in version 0.28.8.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
exiv2fixed0.28.8+dfsg-1package

Примечания

  • https://github.com/Exiv2/exiv2/security/advisories/GHSA-9mxq-4j5g-5wrp

  • https://github.com/Exiv2/exiv2/pull/3462

  • Testcase: https://github.com/Exiv2/exiv2/commit/191138fef73f331de1311e735d8e6359a36fa786 (v0.28.8)

  • Fixed by: https://github.com/Exiv2/exiv2/commit/5b8f1f4d92b8f27a5a80e0c3d3eb9dce7620d9f1 (v0.28.8)

EPSS

Процентиль: 11%
0.00037
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
26 дней назад

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found. The vulnerability is in the CRW image parser. This issue has been patched in version 0.28.8.

CVSS3: 5.3
redhat
26 дней назад

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found. The vulnerability is in the CRW image parser. This issue has been patched in version 0.28.8.

CVSS3: 8.1
nvd
26 дней назад

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found. The vulnerability is in the CRW image parser. This issue has been patched in version 0.28.8.

EPSS

Процентиль: 11%
0.00037
Низкий