Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-55304

Опубликовано: 29 авг. 2025
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted jpg image file. The bug is fixed in version 0.28.6.

A denial of service flaw was found in exiv2. A quadratic algorithm in the ICC profile parsing code in the jpegBase::readMetadata() function can cause Exiv2 to run for a long time. When Exiv2 is used to read the metadata of a crafted jpg image file, it triggers a denial of service.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10exiv2Fix deferred
Red Hat Enterprise Linux 6exiv2Out of support scope
Red Hat Enterprise Linux 7compat-exiv2-023Out of support scope
Red Hat Enterprise Linux 7compat-exiv2-026Out of support scope
Red Hat Enterprise Linux 7exiv2Out of support scope
Red Hat Enterprise Linux 8compat-exiv2-026Fix deferred
Red Hat Enterprise Linux 8exiv2Fix deferred
Red Hat Enterprise Linux 9exiv2Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-407
https://bugzilla.redhat.com/show_bug.cgi?id=2391806exiv2: Exiv2 has quadratic performance in ICC profile parsing

EPSS

Процентиль: 3%
0.00018
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
11 дней назад

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted jpg image file. The bug is fixed in version 0.28.6.

CVSS3: 5.5
nvd
11 дней назад

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted jpg image file. The bug is fixed in version 0.28.6.

CVSS3: 5.5
debian
11 дней назад

Exiv2 is a C++ library and a command-line utility to read, write, dele ...

github
11 дней назад

Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata

EPSS

Процентиль: 3%
0.00018
Низкий

3.3 Low

CVSS3