← Back

CVE-2021-3482

nvd nist
Published: Apr 8, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.

Affected (7)

Products: Exiv2: Exiv2 · Redhat: Enterprise Linux · Fedoraproject: Fedora · +1 more
Show all products
1 product
Exiv2
1 product
Enterprise Linux
1 product
Fedora
1 product
Debian Linux
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Exiv2
Up to 0.27.3
Version 0.27.4 rc1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0

Timeline

No history available yet.