Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3482

Опубликовано: 08 апр. 2021
Источник: nvd
CVSS3: 6.5
CVSS2: 6.4
EPSS Низкий

Описание

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*:*
Версия до 0.27.3 (включая)
cpe:2.3:a:exiv2:exiv2:0.27.4:rc1:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Конфигурация 4

Одно из

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 43%
0.00202
Низкий

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-20
CWE-787

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.

CVSS3: 6.5
redhat
около 4 лет назад

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.

CVSS3: 6.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 6.5
debian
около 4 лет назад

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. ...

CVSS3: 6.5
github
около 3 лет назад

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.

EPSS

Процентиль: 43%
0.00202
Низкий

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-20
CWE-787