Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-34334

Опубликовано: 08 авг. 2021
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.5.

A flaw was found in Exiv2, a utility and library for image metadata. An attacker can exploit this vulnerability by tricking a victim into processing a specially crafted image file. This can lead to an infinite loop, causing a denial of service (DoS) in the application.

Отчет

This vulnerability exists in Exiv2 where an infinite loop can be triggered when reading metadata from a specially crafted image file, this results in a Low Severity Denial of Service (DoS), as it requires a user to manually interact with a malicious file. While the exploit causes the individual Exiv2 process to hang and consume CPU resources, it does not compromise data confidentiality or integrity, and the impact is contained within the local execution environment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6exiv2Out of support scope
Red Hat Enterprise Linux 7compat-exiv2-023Out of support scope
Red Hat Enterprise Linux 7compat-exiv2-026Out of support scope
Red Hat Enterprise Linux 7exiv2Out of support scope
Red Hat Enterprise Linux 8compat-exiv2-026Fix deferred
Red Hat Enterprise Linux 8exiv2Fix deferred
Red Hat Enterprise Linux 9exiv2Affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1992202exiv2: Exiv2: Denial of Service via crafted image file

EPSS

Процентиль: 62%
0.01104
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 5 лет назад

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.5.

CVSS3: 5.5
nvd
почти 5 лет назад

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.5.

CVSS3: 5.5
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 5.5
debian
почти 5 лет назад

Exiv2 is a command-line utility and C++ library for reading, writing, ...

CVSS3: 6.5
fstec
почти 5 лет назад

Уязвимость библиотеки для управления метаданными медиафайлов Exiv2, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 62%
0.01104
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2021-34334