Описание
Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containing a highly compressed zTXt chunk can cause ExifReader to materialize a disproportionately large Comment value in memory.
EPSS
Процентиль: 39%
0.00465
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-409
CWE-409
Связанные уязвимости
CVSS3: 5.3
github
4 месяца назад
ExifReader is vulnerable to denial of service via unbounded decompression of image metadata
EPSS
Процентиль: 39%
0.00465
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-409
CWE-409