Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-39695

Опубликовано: 08 июл. 2024
Источник: redhat
CVSS3: 6.5

Описание

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

A flaw was found in the Exiv2 library. An out-of-bounds read can be triggered when the metadata of a specially crafted ASF video file is processed, causing the application linked to the library to crash, resulting in a denial of service.

Отчет

The support for the ASF video format was introduced in Exiv2 version 0.28.0. This Exiv2 version is not shipped in any Red Hat product. Therefore, Exiv2 as shipped in Red Hat Enterprise Linux 7, 8, and 9 is not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10exiv2Not affected
Red Hat Enterprise Linux 7compat-exiv2-023Not affected
Red Hat Enterprise Linux 7compat-exiv2-026Not affected
Red Hat Enterprise Linux 7exiv2Not affected
Red Hat Enterprise Linux 8compat-exiv2-026Not affected
Red Hat Enterprise Linux 8exiv2Not affected
Red Hat Enterprise Linux 9exiv2Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2296343exiv2: Out-of-bounds read in AsfVideo::streamProperties

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

CVSS3: 5.3
nvd
больше 1 года назад

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

CVSS3: 6.5
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 5.3
debian
больше 1 года назад

Exiv2 is a command-line utility and C++ library for reading, writing, ...

6.5 Medium

CVSS3