Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-39695

Опубликовано: 08 июл. 2024
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

A flaw was found in the Exiv2 library. An out-of-bounds read can be triggered when the metadata of a specially crafted ASF video file is processed, causing the application linked to the library to crash, resulting in a denial of service.

Отчет

The support for the ASF video format was introduced in Exiv2 version 0.28.0. This Exiv2 version is not shipped in any Red Hat product. Therefore, Exiv2 as shipped in Red Hat Enterprise Linux 7, 8, and 9 is not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10exiv2Not affected
Red Hat Enterprise Linux 7compat-exiv2-023Not affected
Red Hat Enterprise Linux 7compat-exiv2-026Not affected
Red Hat Enterprise Linux 7exiv2Not affected
Red Hat Enterprise Linux 8compat-exiv2-026Not affected
Red Hat Enterprise Linux 8exiv2Not affected
Red Hat Enterprise Linux 9exiv2Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2296343exiv2: Out-of-bounds read in AsfVideo::streamProperties

EPSS

Процентиль: 44%
0.00561
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

CVSS3: 5.3
nvd
около 2 лет назад

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

CVSS3: 5.3
msrc
больше 1 года назад

Exiv2 has an out-of-bounds read in AsfVideo::streamProperties

CVSS3: 5.3
debian
около 2 лет назад

Exiv2 is a command-line utility and C++ library for reading, writing, ...

suse-cvrf
5 месяцев назад

Security update for exiv2

EPSS

Процентиль: 44%
0.00561
Низкий

6.5 Medium

CVSS3