CVE-2021-22204: ExifTool Remote Code Execution Vulnerability
Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libimage-exiftool-perlto a version that resolves this vulnerability.Fixed in 11.16-1+deb10u1Fixed in 12.16+dfsg-2Fixed in 12.57+dfsg-1Fixed in 12.67+dfsg-1 - Upgrade
Upgrade
debian/libimage-exiftool-perlto a version that resolves this vulnerability.Fixed in 12.16+dfsg-2Fixed in 11.16-1+deb10u1 - Upgrade
Upgrade
debian/libimage-exiftool-perlto a version that resolves this vulnerability.Fixed in 11.16-1+deb10u1 - Upgrade
Upgrade
debian/libimage-exiftool-perlto a version that resolves this vulnerability.Fixed in 12.16+dfsg-2 - Upgrade
Upgrade
debian/libimage-exiftool-perlto a version that resolves this vulnerability.Fixed in 12.57+dfsg-1 - Upgrade
Upgrade
debian/libimage-exiftool-perlto a version that resolves this vulnerability.Fixed in 12.67+dfsg-1
Event History
Frequently Asked Questions
What is CVE-2021-22204?
CVE-2021-22204 is a vulnerability in ExifTool that allows for remote code execution.
Which versions of ExifTool are affected by CVE-2021-22204?
ExifTool versions 7.44 and up are affected by CVE-2021-22204.
What is the severity of CVE-2021-22204?
CVE-2021-22204 has a severity rating of 7.8 (high).
How can arbitrary code be executed using CVE-2021-22204?
Arbitrary code execution can occur when parsing a malicious DjVu file in ExifTool affected by CVE-2021-22204.
How can I fix CVE-2021-22204?
To fix CVE-2021-22204, update ExifTool to version 12.24 or later.