First published: Fri Apr 23 2021(Updated: )
Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Credit: cve@gitlab.com cve@gitlab.com cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libimage-exiftool-perl | 11.16-1+deb10u1 12.16+dfsg-2 12.57+dfsg-1 12.67+dfsg-1 | |
Exiftool Project Exiftool | >=7.44<12.24 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
debian/libimage-exiftool-perl | <=11.16-1<=7.89-1<=12.16+dfsg-1 | 12.16+dfsg-2 11.16-1+deb10u1 |
>=7.44<12.24 | ||
=9.0 | ||
=10.0 | ||
=32 | ||
=33 | ||
=34 | ||
Perl Exiftool |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22204 is a vulnerability in ExifTool that allows for remote code execution.
ExifTool versions 7.44 and up are affected by CVE-2021-22204.
CVE-2021-22204 has a severity rating of 7.8 (high).
Arbitrary code execution can occur when parsing a malicious DjVu file in ExifTool affected by CVE-2021-22204.
To fix CVE-2021-22204, update ExifTool to version 12.24 or later.