Back to search
CVE-2021-3482
Published: Apr 8, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.
| Vendor | Product | Versions |
|---|---|---|
n/a | exiv2 | affected exiv2 0.27.4RC2 |
Weaknesses (CWE)
References
https://bugzilla.redhat.com/show_bug.cgi?id=1946314
x_refsource_MISC
FEDORA-2021-10d7331a31
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-be94728b95
vendor-advisory
x_refsource_FEDORA
DSA-4958
vendor-advisory
x_refsource_DEBIAN
[debian-lts-announce] 20210830 [SECURITY] [DLA 2750-1] exiv2 security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now