Code Injection in ExifTool - CVE-2021-22204
Published: May 3, 2021 / Updated: June 21, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when parsing DjVu files in ExifTool. A remote attacker can pass a specially crafted file to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Fedora
Ubuntu
libimage-exiftool-perl (Debian package)
libimage-exiftool-perl (Ubuntu package)
perl-Image-ExifTool
media-libs/exiftool
How to mitigate CVE-2021-22204
libimage-exiftool-perl (Debian package) - update to 11.16-1+deb10u1
libimage-exiftool-perl (Ubuntu package) - addressed in versions 10.80-1ubuntu0.1, 11.88-1ubuntu0.1, 12.05-1ubuntu0.1, 12.16+dfsg-1ubuntu0.1
perl-Image-ExifTool - addressed in versions 12.16-3.el7, 12.16-3.el8, 12.16-3.fc32, 12.16-3.fc33, 12.16-3.fc34
media-libs/exiftool - update to 12.42
Links to Public Exploits and PoC-codes
- Exploit #10083 - CVE-2021-22204 (CVE-2021-22204 exploit script) (June 21, 2024)
- Exploit #9117 - CVE-2021-22204 () (June 18, 2023)
- Exploit #9071 - CVE-2021-22204-exiftool (exiftool exploit) (May 14, 2023)
- Exploit #8767 - CVE-2021-22204-exiftool (exiftool exploit) (January 23, 2023)
- Exploit #8224 - CVE-2021-22204 (A complete PoC for CVE-2021-22204 exiftool RCE ) (August 7, 2022)
- Exploit #7881 - CVE-2021-22204-exiftool (exiftool exploit) (May 23, 2022)
- Exploit #7799 - ExifTool 12.23 - Arbitrary Code Execution (May 13, 2022)
- Exploit #7765 - ExifTool 12.23 Arbitrary Code Execution (May 11, 2022)
- Exploit #7709 - exploit-CVE-2021-22204 (Exploit for CVE-2021-22204 (ExifTool) - Arbitrary Code Execution) (May 1, 2022)
- Exploit #7541 - CVE-2021-22204 (Script en python para crear imagenes maliciosas (reverse shell)) (March 27, 2022)
- Exploit #7260 - CVE-2021-22204 () (January 25, 2022)
- Exploit #7212 - CVE-2021-22204 () (December 29, 2021)
- Exploit #7105 - CVE-2021-22204-RSE (reverse shell execution exploit of CVE 22204) (December 7, 2021)
- Exploit #7039 - GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated) (November 25, 2021)
- Exploit #6987 - CVE-2021-22204-Gitlab (Modification of gitlab exploit anything under 13.10) (November 4, 2021)
- Exploit #6977 - GitLab Unauthenticated Remote ExifTool Command Injection (November 3, 2021)
- Exploit #6891 - CVE-2021-22204-exiftool (Python exploit for the CVE-2021-22204 vulnerability in Exiftool) (October 14, 2021)
- Exploit #6647 - CVE (A collection of proof-of-concept exploit scripts written by the STAR Labs team for various CVEs that they discovered or found by others.) (August 23, 2021)
- Exploit #6593 - CVE-2021-22204 () (August 2, 2021)
- Exploit #6592 - CVE-2021-22204 () (August 2, 2021)
- Exploit #5478 - POC-CVE-2021-22204 (POC for exiftool vuln (CVE-2021-22204).) (May 24, 2021)
- Exploit #5446 - CVE-2021-22204 (exiftool arbitrary code execution vulnerability) (May 18, 2021)
- Exploit #5394 - ExifTool DjVu ANT Perl injection (May 12, 2021)
External References
Related Security Bulletins
- Remote code executioin in ExifTool
- Debian update for libimage-exiftool-perl
- Ubuntu update for libimage-exiftool-perl
- Gentoo update for ExifTool
- Fedora EPEL 7 update for perl-Image-ExifTool
- Fedora EPEL 8 update for perl-Image-ExifTool
- Fedora 32 update for perl-Image-ExifTool
- Fedora 33 update for perl-Image-ExifTool
- Fedora 34 update for perl-Image-ExifTool