cbcvebase.

Debian Exiv2 vulnerabilities

73 known vulnerabilities affecting debian/exiv2.

Total CVEs
73
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM33LOW33

Vulnerabilities

Page 3 of 4
CVE-2019-13112P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2019
CVE-2019-13112 [MEDIUM] CVE-2019-13112: exiv2 - A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.... A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file. Scope: local bookworm: resolved (fixed in 0.27.2-6) bullseye: resolved (fixed in 0.27.2-6) forky: resolved (fixed in 0.27.2-6) sid: resolved (fixed in 0.27.2-6) t
debian
CVE-2020-18899P4MEDIUMCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2020
CVE-2020-18899 [MEDIUM] CVE-2020-18899: exiv2 - An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) func... An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. Scope: local bookworm: resolved (fixed in 0.27.2-6) bullseye: resolved (fixed in 0.27.2-6) forky: resolved (fixed in 0.27.2-6) sid: resolved (fixed in 0.27.2-6) trixie: resolved (fixed in 0.27.2-6
debian
CVE-2019-13108P4LOWCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2019
CVE-2019-13108 [MEDIUM] CVE-2019-13108: exiv2 - An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial... An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffset. Scope: local bookworm: resolved (fixed in 0.27.2-6) bullseye: resolved (fixed in 0.27.2-6) forky: resolved (fixed in 0.27.2-6) sid: resolved (fixed in 0.27.2-6) trixi
debian
CVE-2018-19535P4MEDIUMCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2018
CVE-2018-19535 [MEDIUM] CVE-2018-19535: exiv2 - In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cp... In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-based buffer over-read) via a crafted PNG file. Scope: local bookworm: resolved (fixed in 0.27.2-6) bullseye: resolved (fixed in 0.27.2-6) forky: resolved (fixed in 0.27.2-6) sid: resolved (fixed in 0.27.2-6) trixie: resolv
debian
CVE-2019-14369P4MEDIUMCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2019
CVE-2019-14369 [MEDIUM] CVE-2019-14369: exiv2 - Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attack... Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file. Scope: local bookworm: resolved (fixed in 0.27.2-6) bullseye: resolved (fixed in 0.27.2-6) forky: resolved (fixed in 0.27.2-6) sid: resolved (fixed in 0.27.2-6) trixie: resolved (fixed in 0.27.2-6)
debian
CVE-2019-14370P4MEDIUMCVSS 6.5fixed in exiv2 0.27.2-6 (bookworm)2019
CVE-2019-14370 [MEDIUM] CVE-2019-14370: exiv2 - In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetad... In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in denial of service. Scope: local bookworm: resolved (fixed in 0.27.2-6) bullseye: resolved (fixed in 0.27.2-6) forky: resolved (fixed in 0.27.2-6) sid: resolved (fixed in 0.27.2-6) trixie: resolved (fixed in 0.27.2-6)
debian
CVE-2014-9449P4MEDIUMCVSS 5.0fixed in exiv2 0.24-4.1 (bookworm)2014
CVE-2014-9449 [MEDIUM] CVE-2014-9449: exiv2 - Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in E... Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in Exiv2 0.24 allows remote attackers to cause a denial of service (crash) via a long IKEY INFO tag value in an AVI file. Scope: local bookworm: resolved (fixed in 0.24-4.1) bullseye: resolved (fixed in 0.24-4.1) forky: resolved (fixed in 0.24-4.1) sid: resolved (fixed in 0.24-4.1) trixie: res
debian
CVE-2021-29458P4MEDIUMCVSS 5.5fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-29458 [MEDIUM] CVE-2021-29458: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial
debian
CVE-2021-37622P4MEDIUMCVSS 5.5fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37622 [MEDIUM] CVE-2021-37622: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of serv
debian
CVE-2021-37623P4MEDIUMCVSS 5.5fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37623 [MEDIUM] CVE-2021-37623: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of serv
debian
CVE-2024-24826P4MEDIUMCVSS 5.5fixed in exiv2 0.28.3+dfsg-2 (forky)2024
CVE-2024-24826 [MEDIUM] CVE-2024-24826: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.1. The vulnerable function, `QuickTimeVideo::NikonTagsDecoder`, was new in v0.28.0, so Exiv2 versions before v0.28 are _not_ affected. The out-of-bounds read is triggered when Exiv2 is used
debian
CVE-2021-32617P4MEDIUMCVSS 4.7fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-32617 [MEDIUM] CVE-2021-32617: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vul
debian
CVE-2021-37618P4MEDIUMCVSS 4.7fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37618 [MEDIUM] CVE-2021-37618: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denia
debian
CVE-2021-37619P4MEDIUMCVSS 4.7fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37619 [MEDIUM] CVE-2021-37619: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial
debian
CVE-2021-34335P4MEDIUMCVSS 4.7fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-34335 [MEDIUM] CVE-2021-34335: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A floating point exception (FPE) due to an integer divide by zero was found in Exiv2 versions v0.27.4 and earlier. The FPE is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the v
debian
CVE-2021-29463P4LOWCVSS 3.3fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-29463 [LOW] CVE-2021-29463: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of
debian
CVE-2017-17669P4MEDIUMCVSS 5.5fixed in exiv2 0.27.2-6 (bookworm)2017
CVE-2017-17669 [MEDIUM] CVE-2017-17669: exiv2 - There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTC... There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunk_int.cpp in Exiv2 0.26. A crafted PNG file will lead to a remote denial of service attack. Scope: local bookworm: resolved (fixed in 0.27.2-6) bullseye: resolved (fixed in 0.27.2-6) forky: resolved (fixed in 0.27.2-6) sid: resolved (fixed in 0.27.2-6) trixie: res
debian
CVE-2021-37621P4MEDIUMCVSS 5.5fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37621 [MEDIUM] CVE-2021-37621: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of servi
debian
CVE-2021-32815P4MEDIUMCVSS 5.5fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-32815 [MEDIUM] CVE-2021-32815: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a craf
debian
CVE-2021-37616P4MEDIUMCVSS 5.5fixed in exiv2 0.27.5-1 (bookworm)2021
CVE-2021-37616 [MEDIUM] CVE-2021-37616: exiv2 - Exiv2 is a command-line utility and C++ library for reading, writing, deleting, ... Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. The null pointer dereference is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to ca
debian
Debian Exiv2 vulnerabilities | cvebase