Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-39695

Опубликовано: 08 июл. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.3

Описание

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
mantic

not-affected

code not present
noble

not-affected

code not present
upstream

not-affected

debian: Vulnerable code not present

Показывать по

EPSS

Процентиль: 44%
0.00561
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
около 2 лет назад

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

CVSS3: 5.3
nvd
около 2 лет назад

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

CVSS3: 5.3
msrc
больше 1 года назад

Exiv2 has an out-of-bounds read in AsfVideo::streamProperties

CVSS3: 5.3
debian
около 2 лет назад

Exiv2 is a command-line utility and C++ library for reading, writing, ...

suse-cvrf
5 месяцев назад

Security update for exiv2

EPSS

Процентиль: 44%
0.00561
Низкий

5.3 Medium

CVSS3