Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-39695

Опубликовано: 08 июл. 2024
Источник: nvd
CVSS3: 5.3
CVSS3: 6.5
EPSS Низкий

Описание

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*:*
Версия от 0.28.0 (включая) до 0.28.3 (исключая)

EPSS

Процентиль: 53%
0.00296
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-125
CWE-125

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

CVSS3: 6.5
redhat
больше 1 года назад

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

CVSS3: 6.5
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 5.3
debian
больше 1 года назад

Exiv2 is a command-line utility and C++ library for reading, writing, ...

EPSS

Процентиль: 53%
0.00296
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-125
CWE-125