CVE-2021-31292: Buffer Overflow
Published Jul 26, 2021
·Updated
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
Affected Software
7 affected componentsFixes available
debian/exiv2
0.25-4+deb10u20.25-4+deb10u40.27.3-3+deb11u20.27.3-3+deb11u10.27.6-1
redhat/exiv2<0.27.4
0.27.4
exiv2 exiv2=0.27.3
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Remediation
Patch Available
Event History
Jul 26, 2021
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-31292?
The severity of CVE-2021-31292 is high with a CVSS score of 7.5.
2
How can attackers exploit CVE-2021-31292?
Attackers can trigger a heap-based buffer overflow and cause a denial of service by exploiting the integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3.
3
What software versions are affected by CVE-2021-31292?
Exiv2 versions 0.25-4+deb10u2, 0.25-4+deb10u4, 0.27.3-3+deb11u2, 0.27.3-3+deb11u1, and 0.27.6-1 are affected by CVE-2021-31292.
4
Where can I find more information about CVE-2021-31292?
You can find more information about CVE-2021-31292 on the GitHub pages and the Debian security tracker provided in the references.