VYPR
Medium severity6.5NVD Advisory· Published Apr 8, 2021· Updated Jun 17, 2026

CVE-2021-3482

CVE-2021-3482

Description

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

13
  • Exiv2/Exiv23 versions
    cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*:*range: <=0.27.3
    • cpe:2.3:a:exiv2:exiv2:0.27.4:rc1:*:*:*:*:*:*
    • (no CPE)range: <=0.27.4-RC1
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
  • Exiv2/Exiv2description
  • osv-coords4 versions
    < 0.27.4-5.el8+ 3 more
    • (no CPE)range: < 0.27.4-5.el8
    • (no CPE)range: < 0.27.4-5.el8
    • (no CPE)range: < 0.27.4-5.el8
    • (no CPE)range: < 0.27.4-5.el8

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.