Debian Exiv2 vulnerabilities

125 known vulnerabilities affecting debian/exiv2.

Total CVEs
125
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM33LOW85

Vulnerabilities

Page 1 of 7
CVE-2026-25884LOWCVSS 2.7fixed in exiv2 0.28.8+dfsg-1 (forky)2026
CVE-2026-25884 [LOW] CVE-2026-25884: exiv2 - Exiv2 is a C++ library and a command-line utility to read, write, delete and mod... Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found. The vulnerability is in the CRW image parser. This issue has been patched in version 0.28.8. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 0.28.8+dfsg-1) sid: resolve
debian
CVE-2026-27631LOWCVSS 2.7fixed in exiv2 0.28.8+dfsg-1 (forky)2026
CVE-2026-27631 [LOW] CVE-2026-27631: exiv2 - Exiv2 is a C++ library and a command-line utility to read, write, delete and mod... Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an uncaught exception was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. Due to an integer overflow, the code attemp
debian
CVE-2026-27596LOWCVSS 2.7fixed in exiv2 0.28.8+dfsg-1 (forky)2026
CVE-2026-27596 [LOW] CVE-2026-27596: exiv2 - Exiv2 is a C++ library and a command-line utility to read, write, delete and mod... Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. The out-of-bounds read is at a 4GB offset,
debian
CVE-2025-54080LOWCVSS 1.8fixed in exiv2 0.28.7+dfsg-2 (forky)2025
CVE-2025-54080 [LOW] CVE-2025-54080: exiv2 - Exiv2 is a C++ library and a command-line utility to read, write, delete and mod... Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions 0.28.5 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of
debian
CVE-2025-55304LOWCVSS 1.8fixed in exiv2 0.28.7+dfsg-2 (forky)2025
CVE-2025-55304 [LOW] CVE-2025-55304: exiv2 - Exiv2 is a C++ library and a command-line utility to read, write, delete and mod... Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time. The denial-of-service is triggered when Exiv2 is used to read the meta
debian
CVE-2025-26623LOWCVSS 5.3fixed in exiv2 0.28.4+dfsg-2 (forky)2025
CVE-2025-26623 [MEDIUM] CVE-2025-26623: exiv2 - Exiv2 is a C++ library and a command-line utility to read, write, delete and mod... Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A heap buffer overflow was found in Exiv2 versions v0.28.0 to v0.28.4. Versions prior to v0.28.0, such as v0.27.7, are **not** affected. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata
debian
CVE-2024-25112MEDIUMCVSS 5.5fixed in exiv2 0.28.3+dfsg-2 (forky)2024
CVE-2024-25112 [MEDIUM] CVE-2024-25112: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-service was found in Exiv2 version v0.28.1: an unbounded recursion can cause Exiv2 to crash by exhausting the stack. The vulnerable function, `QuickTimeVideo::multipleEntriesDecoder`, was new in v0.28.0, so Exiv2 versions before v0.2
debian
CVE-2024-24826MEDIUMCVSS 5.5fixed in exiv2 0.28.3+dfsg-2 (forky)2024
CVE-2024-24826 [MEDIUM] CVE-2024-24826: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.1. The vulnerable function, `QuickTimeVideo::NikonTagsDecoder`, was new in v0.28.0, so Exiv2 versions before v0.28 are _not_ affected. The out-of-bounds read is triggered when Exiv2 is used
debian
CVE-2024-39695LOWCVSS 5.32024
CVE-2024-39695 [MEDIUM] CVE-2024-39695: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted v
debian
CVE-2023-44398LOWCVSS 8.82023
CVE-2023-44398 [HIGH] CVE-2023-44398: exiv2 - Exiv2 is a C++ library and a command-line utility to read, write, delete and mod... Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, `BmffImage::brotliUncompress`, is new in v0.28.0, so earlier versions of Exiv2 are _not_ affected. The out-of-bounds write is triggered when Exiv2 is used to read
debian
CVE-2021-29457HIGHCVSS 7.8fixed in exiv2 0.27.3-3.1 (bookworm)2021
CVE-2021-29457 [HIGH] CVE-2021-29457: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to gain code execution,
debian
CVE-2021-31292HIGHCVSS 7.5fixed in exiv2 0.27.3-3.1 (bookworm)2021
CVE-2021-31292 [HIGH] CVE-2021-31292: exiv2 - An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to ... An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. Scope: local bookworm: resolved (fixed in 0.27.3-3.1) bullseye: resolved (fixed in 0.27.3-3+deb11u1) forky: resolved (fixed in 0.27.3-3.1) sid: resolved (fixed in 0.27.3-3.1) trixie: resolved (fi
debian
CVE-2021-37621MEDIUMCVSS 5.5fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37621 [MEDIUM] CVE-2021-37621: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of servi
debian
CVE-2021-3482MEDIUMCVSS 6.5fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-3482 [MEDIUM] CVE-2021-3482: exiv2 - A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper ... A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a crafted JPG image containing malicious EXIF data. Scope: local bookworm: resolved (fixed in 0.27.5-1) bullseye: resolved (fixed in 0.27.3-3+deb11u2) fork
debian
CVE-2021-37623MEDIUMCVSS 5.5fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37623 [MEDIUM] CVE-2021-37623: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of serv
debian
CVE-2021-37620MEDIUMCVSS 4.7fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37620 [MEDIUM] CVE-2021-37620: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial
debian
CVE-2021-32617MEDIUMCVSS 4.7fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-32617 [MEDIUM] CVE-2021-32617: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vul
debian
CVE-2021-37622MEDIUMCVSS 5.5fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37622 [MEDIUM] CVE-2021-37622: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of serv
debian
CVE-2021-37618MEDIUMCVSS 4.7fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37618 [MEDIUM] CVE-2021-37618: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denia
debian
CVE-2021-37619MEDIUMCVSS 4.7fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37619 [MEDIUM] CVE-2021-37619: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial
debian