Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-24614

Опубликовано: 24 фев. 2022
Источник: redhat
CVSS3: 5.5

Описание

When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6metadata-extractorOut of support scope
Red Hat Integration Camel K 1metadata-extractorFix deferred
Red Hat Integration Camel Quarkus 1metadata-extractorFix deferred
Red Hat JBoss BRMS 5metadata-extractorOut of support scope
Red Hat JBoss BRMS 6metadata-extractorOut of support scope
Red Hat JBoss Data Virtualization 6metadata-extractorOut of support scope
Red Hat JBoss Fuse 6metadata-extractorOut of support scope
Red Hat JBoss Fuse Service Works 6metadata-extractorOut of support scope
Red Hat Fuse 7.11metadata-extractorFixedRHSA-2022:553207.07.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2058763metadata-extractor: Out-of-memory when reading a specially crafted JPEG file

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 4 года назад

When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library.

CVSS3: 5.5
nvd
почти 4 года назад

When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library.

CVSS3: 5.5
debian
почти 4 года назад

When reading a specially crafted JPEG file, metadata-extractor up to 2 ...

CVSS3: 5.5
github
почти 4 года назад

Allocation of Resources Without Limits or Throttling in metadata-extractor

5.5 Medium

CVSS3