CVE Database
/

CVE-2021-3482

Back to search

CVE-2021-3482

Published: Apr 8, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.

VendorProductVersions

n/a

exiv2

affected
exiv2 0.27.4RC2

Weaknesses (CWE)

References

FEDORA-2021-10d7331a31
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-be94728b95
vendor-advisory
x_refsource_FEDORA
DSA-4958
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now