Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, BmffImage::brotliUncompress, is new in v0.28.0, so earlier versions of Exiv2 are not affected. The out-of-bounds write is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to gain code execution, if they can trick the victim into running Exiv2 on a crafted image file. This bug is fixed in version v0.28.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file.
A float point exception in the printLong function in tagsint.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input.
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when printing the image ICC profile, which is a less frequently used Exiv2 operation that requires an extra command line option (-p C). The bug is fixed in version v0.27.5.
Reference: https://github.com/Exiv2/exiv2/security/advisories/GHSA-583f-w9pm-99r2
Upstream patch: https://github.com/Exiv2/exiv2/pull/1759
In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
Upstream Issue:
https://github.com/Exiv2/exiv2/issues/1011
Upstream Fix:
https://github.com/Exiv2/exiv2/commit/a82098f4f90cd86297131b5663c3dec6a34470e8
In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can lead to a buffer overflow vulnerability and a crash.
Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.
An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in the file bigtiffimage.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack.
Upstream issue:
https://github.com/Exiv2/exiv2/issues/590
References:
https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack.
Upstream issue:
https://github.com/Exiv2/exiv2/issues/590
References:
https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimageint.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack.
Upstream issue:
https://github.com/Exiv2/exiv2/issues/590
References:
https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack.
Upstream issue:
https://github.com/Exiv2/exiv2/issues/590
References:
https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack.
Upstream issue:
https://github.com/Exiv2/exiv2/issues/590
References:
https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206
There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack.
Upstream issue:
https://github.com/Exiv2/exiv2/issues/590
References:
https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a denial of service attack.
Upstream issue:
https://github.com/Exiv2/exiv2/issues/590
References:
https://github.com/TeamSeri0us/pocs/tree/master/exiv2/20181206
An issue was found in Exiv2 v0.27-RC2. A NULL pointer dereference in Exiv2::isoSpeed in easyaccess.cpp allows remote attackers to cause a denial of service via a crafted file.
References: https://github.com/Exiv2/exiv2/issues/561
An issue was found in Exiv2 0.26 and previous versions. A heap-based buffer over-read in PngChunk::readRawProfile function in pngchunkint.cpp may cause a denial of service via a crafted PNG file.
References: https://github.com/Exiv2/exiv2/issues/428 https://github.com/Exiv2/exiv2/pull/430
An issue was found in Exiv2 v0.27-RC2. A NULL pointer dereference in Exiv2::isoSpeed in easyaccess.cpp allows remote attackers to cause a denial of service via a crafted file.
References: https://github.com/Exiv2/exiv2/issues/561
A flaw was found in Exiv2 0.26. An infinite loop in Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader. This could lead to a denial of service caused by an integer overflow via a crafted PSD image file.
References: https://github.com/Exiv2/exiv2/issues/426
Upstream Patch: https://github.com/Exiv2/exiv2/pull/518
A flaw was found in Exiv2 0.26. A heap-based buffer over-read in Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader). This could lead to a denial of service caused by an integer overflow via a crafted PSD image file.
References: https://github.com/Exiv2/exiv2/issues/427
Upstream Patch: https://github.com/Exiv2/exiv2/pull/518
A flaw was found in Exiv2 0.27-RC1. An infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp. A crafted input will lead to a remote denial of service attack.
References: https://github.com/Exiv2/exiv2/issues/511
Upstream Patch: https://github.com/Exiv2/exiv2/pull/517
A flaw was found in Exiv2 0.27-RC1. An infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp. A crafted input will lead to a remote denial of service attack.
References: https://github.com/Exiv2/exiv2/issues/511
Upstream Patch: https://github.com/Exiv2/exiv2/pull/517
A flaw was found in Exiv2 0.26. The CiffDirectory::readDirectory() function at crwimageint.cpp has an excessive stack consumption due to a recursive function, leading to Denial of service.
References: https://github.com/Exiv2/exiv2/issues/460 https://github.com/SegfaultMasters/covering360/blob/master/Exiv2
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
References: https://github.com/Exiv2/exiv2/issues/457
A flaw was found in Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
References: https://github.com/Exiv2/exiv2/issues/455