Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-27815

Опубликовано: 25 фев. 2021
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.

Отчет

This only affects the command line utility, which is not shipped as part of libexif.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libexifNot affected
Red Hat Enterprise Linux 7libexifNot affected
Red Hat Enterprise Linux 8libexifNot affected
Red Hat Enterprise Linux 9libexifNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1958807libexif: NULL Pointer Deference may lead to DoS by uploading a malicious JPEG file

EPSS

Процентиль: 44%
0.00215
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 5 лет назад

NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.

CVSS3: 5.5
nvd
почти 5 лет назад

NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.

CVSS3: 5.5
debian
почти 5 лет назад

NULL Pointer Deference in the exif command line tool, when printing ou ...

CVSS3: 5.5
github
больше 3 лет назад

NULL Pointer Deference in the "actions.c" library of libexif exif v0.6.22 allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.

EPSS

Процентиль: 44%
0.00215
Низкий

5.5 Medium

CVSS3