rpm package
almalinux/exiv2-devel
pkg:rpm/almalinux/exiv2-devel
Vulnerabilities (43)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-26623 | — | < 0.28.3-3.el10_0.2 | 0.28.3-3.el10_0.2 | Feb 18, 2025 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A heap buffer overflow was found in Exiv2 versions v0.28.0 to v0.28.4. Versions prior to v0.28.0, such as v0.27.7, are **not** affected. Exiv2 is a command- | ||
| CVE-2020-18898 | — | < 0.27.5-2.el8 | 0.27.5-2.el8 | Aug 19, 2021 | A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file. | ||
| CVE-2021-37619 | — | < 0.27.4-5.el8 | 0.27.4-5.el8 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte | ||
| CVE-2021-37618 | — | < 0.27.4-5.el8 | 0.27.4-5.el8 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a craf | ||
| CVE-2021-31292 | — | < 0.27.4-5.el8 | 0.27.4-5.el8 | Jul 26, 2021 | An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. | ||
| CVE-2021-32617 | — | < 0.27.4-5.el8 | 0.27.4-5.el8 | May 17, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to | ||
| CVE-2021-29623 | — | < 0.27.4-5.el8 | 0.27.4-5.el8 | May 13, 2021 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleti | ||
| CVE-2021-29464 | — | < 0.27.4-5.el8 | 0.27.4-5.el8 | Apr 30, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted im | ||
| CVE-2021-29463 | — | < 0.27.4-5.el8 | 0.27.4-5.el8 | Apr 30, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte | ||
| CVE-2021-29473 | — | < 0.27.4-5.el8 | 0.27.4-5.el8 | Apr 26, 2021 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and m | ||
| CVE-2021-29470 | — | < 0.27.4-5.el8 | 0.27.4-5.el8 | Apr 23, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte | ||
| CVE-2021-29458 | — | < 0.27.4-5.el8 | 0.27.4-5.el8 | Apr 19, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte | ||
| CVE-2021-29457 | — | < 0.27.4-5.el8 | 0.27.4-5.el8 | Apr 19, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted im | ||
| CVE-2021-3482 | — | < 0.27.4-5.el8 | 0.27.4-5.el8 | Apr 8, 2021 | A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data. | ||
| CVE-2019-20421 | — | < 0.27.2-5.el8 | 0.27.2-5.el8 | Jan 27, 2020 | In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file. | ||
| CVE-2019-17402 | — | < 0.27.3-2.el8 | 0.27.3-2.el8 | Oct 9, 2019 | Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size. | ||
| CVE-2019-13113 | — | < 0.27.2-5.el8 | 0.27.2-5.el8 | Jun 30, 2019 | Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file. | ||
| CVE-2019-13111 | — | < 0.27.2-5.el8 | 0.27.2-5.el8 | Jun 30, 2019 | A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file. | ||
| CVE-2019-13109 | — | < 0.27.2-5.el8 | 0.27.2-5.el8 | Jun 30, 2019 | An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction. | ||
| CVE-2019-13114 | — | < 0.27.2-5.el8 | 0.27.2-5.el8 | Jun 30, 2019 | http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character. |
- CVE-2025-26623Feb 18, 2025affected < 0.28.3-3.el10_0.2fixed 0.28.3-3.el10_0.2
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A heap buffer overflow was found in Exiv2 versions v0.28.0 to v0.28.4. Versions prior to v0.28.0, such as v0.27.7, are **not** affected. Exiv2 is a command-
- CVE-2020-18898Aug 19, 2021affected < 0.27.5-2.el8fixed 0.27.5-2.el8
A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.
- CVE-2021-37619Aug 9, 2021affected < 0.27.4-5.el8fixed 0.27.4-5.el8
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte
- CVE-2021-37618Aug 9, 2021affected < 0.27.4-5.el8fixed 0.27.4-5.el8
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a craf
- CVE-2021-31292Jul 26, 2021affected < 0.27.4-5.el8fixed 0.27.4-5.el8
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
- CVE-2021-32617May 17, 2021affected < 0.27.4-5.el8fixed 0.27.4-5.el8
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to
- CVE-2021-29623May 13, 2021affected < 0.27.4-5.el8fixed 0.27.4-5.el8
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleti
- CVE-2021-29464Apr 30, 2021affected < 0.27.4-5.el8fixed 0.27.4-5.el8
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted im
- CVE-2021-29463Apr 30, 2021affected < 0.27.4-5.el8fixed 0.27.4-5.el8
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte
- CVE-2021-29473Apr 26, 2021affected < 0.27.4-5.el8fixed 0.27.4-5.el8
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and m
- CVE-2021-29470Apr 23, 2021affected < 0.27.4-5.el8fixed 0.27.4-5.el8
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte
- CVE-2021-29458Apr 19, 2021affected < 0.27.4-5.el8fixed 0.27.4-5.el8
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte
- CVE-2021-29457Apr 19, 2021affected < 0.27.4-5.el8fixed 0.27.4-5.el8
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted im
- CVE-2021-3482Apr 8, 2021affected < 0.27.4-5.el8fixed 0.27.4-5.el8
A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data.
- CVE-2019-20421Jan 27, 2020affected < 0.27.2-5.el8fixed 0.27.2-5.el8
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
- CVE-2019-17402Oct 9, 2019affected < 0.27.3-2.el8fixed 0.27.3-2.el8
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.
- CVE-2019-13113Jun 30, 2019affected < 0.27.2-5.el8fixed 0.27.2-5.el8
Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.
- CVE-2019-13111Jun 30, 2019affected < 0.27.2-5.el8fixed 0.27.2-5.el8
A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.
- CVE-2019-13109Jun 30, 2019affected < 0.27.2-5.el8fixed 0.27.2-5.el8
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.
- CVE-2019-13114Jun 30, 2019affected < 0.27.2-5.el8fixed 0.27.2-5.el8
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
Page 1 of 3