Back

MEDIUM

Out-of-bounds read in XmpTextValue::read()

Published Aug 9, 2021

Description

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.5.

Affected products

Remediation

Red Hat statement

To exploit this issue, an attacker needs to convince a user to process a specially crafted image file, specifically to read medatada of an image. Additionally, this flaw can lead to an out-of-bounds read and cause a denial of service with no other security impact. Due to these reasons, this vulnerability has been rated with a low severity.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 9, 2021
Updated Aug 4, 2024
Reserved Jul 29, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 8, 2021
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a