VYPR

rpm package

almalinux/exiv2

pkg:rpm/almalinux/exiv2

Vulnerabilities (14)

  • CVE-2025-26623CriFeb 18, 2025
    affected < 0.28.3-3.el10_0.2fixed 0.28.3-3.el10_0.2

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A heap buffer overflow was found in Exiv2 versions v0.28.0 to v0.28.4. Versions prior to v0.28.0, such as v0.27.7, are **not** affected. Exiv2 is a command-

  • CVE-2020-18898MedAug 19, 2021
    affected < 0.27.5-2.el8fixed 0.27.5-2.el8

    A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.

  • CVE-2021-37619MedAug 9, 2021
    affected < 0.27.4-5.el8fixed 0.27.4-5.el8

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte

  • CVE-2021-37618MedAug 9, 2021
    affected < 0.27.4-5.el8fixed 0.27.4-5.el8

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a craf

  • CVE-2021-31292HigJul 26, 2021
    affected < 0.27.4-5.el8fixed 0.27.4-5.el8

    An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.

  • CVE-2021-32617MedMay 17, 2021
    affected < 0.27.4-5.el8fixed 0.27.4-5.el8

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to

  • CVE-2021-29623LowMay 13, 2021
    affected < 0.27.4-5.el8fixed 0.27.4-5.el8

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleti

  • CVE-2021-29464LowApr 30, 2021
    affected < 0.27.4-5.el8fixed 0.27.4-5.el8

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted im

  • CVE-2021-29463LowApr 30, 2021
    affected < 0.27.4-5.el8fixed 0.27.4-5.el8

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte

  • CVE-2021-29473LowApr 26, 2021
    affected < 0.27.4-5.el8fixed 0.27.4-5.el8

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and m

  • CVE-2021-29470MedApr 23, 2021
    affected < 0.27.4-5.el8fixed 0.27.4-5.el8

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte

  • CVE-2021-29458MedApr 19, 2021
    affected < 0.27.4-5.el8fixed 0.27.4-5.el8

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte

  • CVE-2021-29457HigApr 19, 2021
    affected < 0.27.4-5.el8fixed 0.27.4-5.el8

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted im

  • CVE-2021-3482MedApr 8, 2021
    affected < 0.27.4-5.el8fixed 0.27.4-5.el8

    A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.