First published: Wed Apr 14 2021(Updated: )
NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libexif Project Exif | <=0.6.22 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27815 is a vulnerability that allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the exif command line tool to crash.
The Libexif Project Exif version 0.6.22 and earlier, as well as Fedora versions 32, 33, and 34, are affected by CVE-2021-27815.
CVE-2021-27815 has a severity rating of 5.5, which is classified as medium.
To fix CVE-2021-27815, update to a version of exif that includes the following commits: eb84b0e3c5f2a86013b6fcfb800d187896a648fa and f6334d9d32437ef13dc902f0a88a2be0063d9d1c.
The Common Weakness Enumeration (CWE) for CVE-2021-27815 is CWE-476: NULL Pointer Dereference.