CVE-2025-54080: Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file

Published Aug 29, 2025
·
Updated

Impact An out-of-bounds read was found in Exiv2 versions v0.28.5 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file.

Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as delete.

Patches The bug is fixed in version v0.28.6.

Credit Thank you to @dragonArthurX for reporting this issue.

Details (from original report by @dragonArthurX ) Version: Tested on v0.28.5 (latest official release) Commit: 907169fa643c2c74c14fd4106e55eaeee3634d9f

Platform: Ubuntu 20.04.6 LTS (x8664)

Build Steps: bash git clone https://github.com/Exiv2/exiv2.git cd exiv2 git checkout v0.28.5 mkdir build-v0.28.5 && cd build-v0.28.5 cmake -DCMAKECCOMPILER=/fuzzer/afl-clang-fast -DCMAKECXXCOMPILER=/fuzzer/afl-clang-fast++ -DCMAKECFLAGS="-g -fsanitize=address" -DCMAKECXXFLAGS="-g -fsanitize=address" -DBUILDSHAREDLIBS=OFF ../

Command line to reproduce: bash /home/exiv2/build/bin/exiv2 -d a -f /home/poc

Crash Output: AddressSanitizer:DEADLYSIGNAL ================================================================ = ==376531==ERROR: AddressSanitizer: SEGV on unknown address 0x7fd92236b0e7 (pc 0x7fd82314dcd2 bp 0x7ffd540ceba0 sp 0x7ffd540ce358 T0) ==376531==The signal is caused by a READ memory access. #0 0x7fd82314dcd2 /build/glibc-B3wQXB/glibc-2.31/string/../sysdeps/x8664/multiarch/memmove-vec-unaligned-erms.S:383 #1 0x4ed131 in asanmemcpy (/home/exiv2/build-v0.28.5/bin/exiv2+0x4ed131) #2 0x6184b1 in Exiv2::MemIo::write(unsigned char const, unsigned long) /home/exiv2/src/basicio.cpp:704:5 #3 0xad336d in (anonymous namespace)::writeTemp(Exiv2::BasicIo&, unsigned char const, unsigned long) /home/exiv2/src/epsimage.cpp:90:14 #4 0xac3a07 in (anonymous namespace)::readWriteEpsMetadata(Exiv2::BasicIo&, std::cxx11::basicstring<char, std::chartraits<char>, std::allocator<char> >&, std::vector<Exiv2::NativePreview, std::allocator<Exiv2::NativePreview> >&, bool) /home/exiv2/src/epsimage.cpp:1009:7 #5 0xad1175 in Exiv2::EpsImage::writeMetadata() /home/exiv2/src/epsimage.cpp:1103:3 #6 0x5d2383 in Action::Erase::run(std::cxx11::basicstring<char, std::chartraits<char>, std::allocator<char> > const&) /home/exiv2/app/actions.cpp:713:14 #7 0x522d02 in main /home/exiv2/app/exiv2.cpp:177:25 #8 0x7fd8230b6082 in libcstartmain /build/glibc-B3wQXB/glibc-2.31/csu/../csu/libc-start.c:308:16 #9 0x4714dd in start (/home/exiv2/build-v0.28.5/bin/exiv2+0x4714dd)

AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV /build/glibc-B3wQXB/glibc-2.31/string/../sysdeps/x8664/multiarch/memmove-vec-unaligned-erms.S:383 ==376531==ABORTING

Other sources

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions 0.28.5 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. The bug is fixed in version 0.28.6.

MITRE

Affected Software

3 affected components
exiv2 exiv2<0.28.6
pip/Exiv2<=0.17.3
exiv2 exiv2<0.28.6

Event History

Aug 29, 2025
Advisory Published
via GitHub·02:49 PM
Data Sourced
via GitHub·02:49 PM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-54080?

CVE-2025-54080 is considered a high severity vulnerability due to the potential for out-of-bounds read exploitation.

2

How do I fix CVE-2025-54080?

To fix CVE-2025-54080, upgrade Exiv2 to version 0.28.6 or later.

3

What versions are affected by CVE-2025-54080?

CVE-2025-54080 affects Exiv2 versions 0.28.5 and earlier.

4

Can CVE-2025-54080 lead to data corruption?

Yes, CVE-2025-54080 can potentially lead to data corruption as it involves an out-of-bounds read.

5

Is there a known exploit for CVE-2025-54080?

As of now, there are no publicly known exploits specifically targeting CVE-2025-54080.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203