Debian Exiv2 vulnerabilities
73 known vulnerabilities affecting debian/exiv2.
Total CVEs
73
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM33LOW33
Vulnerabilities
Page 2 of 4
CVE-2017-9239P4MEDIUMCVSS 6.5fixed in exiv2 0.25-3.1 (bookworm)2017
CVE-2017-9239 [MEDIUM] CVE-2017-9239: exiv2 - An issue was discovered in Exiv2 0.26. When the data structure of the structure ...
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fault. To exploit this vulnerability, someone must open a crafted tiff file.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2018-19107P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2018
CVE-2018-19107 [MEDIUM] CVE-2018-19107: exiv2 - In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp i...
In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD image file.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolv
debian
CVE-2026-27631P4LOWCVSS 2.7fixed in exiv2 0.28.8+dfsg-1 (forky)2026
CVE-2026-27631 [LOW] CVE-2026-27631: exiv2 - Exiv2 is a C++ library and a command-line utility to read, write, delete and mod...
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an uncaught exception was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. Due to an integer overflow, the code attemp
debian
CVE-2018-16336P4MEDIUMCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2018
CVE-2018-16336 [MEDIUM] CVE-2018-16336: exiv2 - Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers ...
Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE-2018-10999.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.
debian
CVE-2018-11037P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2018
CVE-2018-11037 [MEDIUM] CVE-2018-11037: exiv2 - In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allo...
In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a crafted file.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: resolved (fixed in 0.27.2-6)
debian
CVE-2018-17581P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2018
CVE-2018-17581 [MEDIUM] CVE-2018-17581: exiv2 - CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive s...
CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: resolved (fixed in 0.27.2-6)
debian
CVE-2017-11683P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2017
CVE-2017-11683 [MEDIUM] CVE-2017-11683: exiv2 - There is a reachable assertion in the Internal::TiffReader::visitDirectory funct...
There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: resolved (f
debian
CVE-2018-20097P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2018
CVE-2018-20097 [MEDIUM] CVE-2018-20097: exiv2 - There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffi...
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: resolved (fixed in 0.27
debian
CVE-2018-19108P4MEDIUMCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2018
CVE-2018-19108 [MEDIUM] CVE-2018-19108: exiv2 - In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image re...
In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: re
debian
CVE-2019-17402P4MEDIUMCVSS 6.5fixed in exiv2 0.27.3-1 (bookworm)2019
CVE-2019-17402 [MEDIUM] CVE-2019-17402: exiv2 - Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp...
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.
Scope: local
bookworm: resolved (fixed in 0.27.3-1)
bullseye: resolved (fixed in 0.27.3-1)
forky: resolved (fi
debian
CVE-2020-19716P4MEDIUMCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2020
CVE-2020-19716 [MEDIUM] CVE-2020-19716: exiv2 - A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0...
A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: resolved (fixed in 0.27.2-6)
debian
CVE-2018-10958P4MEDIUMCVSS 6.5fixed in exiv2 0.25-4 (bookworm)2018
CVE-2018-10958 [MEDIUM] CVE-2018-10958: exiv2 - In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an a...
In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call.
Scope: local
bookworm: resolved (fixed in 0.25-4)
bullseye: resolved (fixed in 0.25-4)
forky: resolved (fixed in 0.25-4)
sid: resolved (fixed in 0.25-4)
trixie: resolved (fixed in 0.25-4)
debian
CVE-2018-10999P4MEDIUMCVSS 6.5fixed in exiv2 0.25-4 (bookworm)2018
CVE-2018-10999 [MEDIUM] CVE-2018-10999: exiv2 - An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTCh...
An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer over-read.
Scope: local
bookworm: resolved (fixed in 0.25-4)
bullseye: resolved (fixed in 0.25-4)
forky: resolved (fixed in 0.25-4)
sid: resolved (fixed in 0.25-4)
trixie: resolved (fixed in 0.25-4)
debian
CVE-2019-13504P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2019
CVE-2019-13504 [MEDIUM] CVE-2019-13504: exiv2 - There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp ...
There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: resolved (fixed in 0.27.2-6)
debian
CVE-2019-13110P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2019
CVE-2019-13110 [MEDIUM] CVE-2019-13110: exiv2 - A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 ...
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: resolved (fixed
debian
CVE-2019-13109P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2019
CVE-2019-13109 [MEDIUM] CVE-2019-13109: exiv2 - An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial...
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27
debian
CVE-2018-10998P4MEDIUMCVSS 6.5fixed in exiv2 0.25-4 (bookworm)2018
CVE-2018-10998 [MEDIUM] CVE-2018-10998: exiv2 - An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remot...
An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.
Scope: local
bookworm: resolved (fixed in 0.25-4)
bullseye: resolved (fixed in 0.25-4)
forky: resolved (fixed in 0.25-4)
sid: resolved (fixed in 0.25-4)
trixie: resolved (fixed in 0.25-4)
debian
CVE-2019-13114P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2019
CVE-2019-13114 [MEDIUM] CVE-2019-13114: exiv2 - http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial ...
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: reso
debian
CVE-2019-13113P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2019
CVE-2019-13113 [MEDIUM] CVE-2019-13113: exiv2 - Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due ...
Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: resolved (fixed in 0.27.2-6)
debian
CVE-2018-8976P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2018
CVE-2018-8976 [MEDIUM] CVE-2018-8976: exiv2 - In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service...
In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a crafted file.
Scope: local
bookworm: resolved (fixed in 0.27.2-6)
bullseye: resolved (fixed in 0.27.2-6)
forky: resolved (fixed in 0.27.2-6)
sid: resolved (fixed in 0.27.2-6)
trixie: resolved (fixed in 0.27.2-6)
debian