Описание
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.5.
A flaw was found in Exiv2, a utility and library for image metadata. An attacker can exploit this vulnerability by tricking a victim into processing a specially crafted image file. This can lead to an infinite loop, causing a denial of service (DoS) in the application.
Отчет
This vulnerability exists in Exiv2 where an infinite loop can be triggered when reading metadata from a specially crafted image file, this results in a Low Severity Denial of Service (DoS), as it requires a user to manually interact with a malicious file. While the exploit causes the individual Exiv2 process to hang and consume CPU resources, it does not compromise data confidentiality or integrity, and the impact is contained within the local execution environment.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | exiv2 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | compat-exiv2-023 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | compat-exiv2-026 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | exiv2 | Out of support scope | ||
| Red Hat Enterprise Linux 8 | compat-exiv2-026 | Fix deferred | ||
| Red Hat Enterprise Linux 8 | exiv2 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | exiv2 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.5.
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.5.
Exiv2 is a command-line utility and C++ library for reading, writing, ...
Уязвимость библиотеки для управления метаданными медиафайлов Exiv2, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.5 Medium
CVSS3