Buffer overflow in Exiv2 - CVE-2021-3482
Published: August 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing EXIF data in Jp2Image::readMetadata() in jp2image.cpp. A remote attacker can create a specially crafted EXIF document, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Arch Linux
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
Fedora
exiv2 (Debian package)
libexiv2-14 (Ubuntu package)
exiv2
exiv2-devel
exiv2-debuginfo
exiv2-debugsource
exiv2-help
libexiv2-27 (Ubuntu package)
exiv2 (Red Hat package)
exiv2-libs
How to mitigate CVE-2021-3482
exiv2 (Debian package) - update to 0.25-4+deb10u2
libexiv2-14 (Ubuntu package) - addressed in versions 0.25-3.1ubuntu0.18.04.7, 0.25-3.1ubuntu0.18.04.11
exiv2 - update to 0.26-25
exiv2-devel - update to 0.26-25
exiv2-debuginfo - update to 0.26-25
exiv2-debugsource - update to 0.26-25
exiv2-help - update to 0.26-25
libexiv2-27 (Ubuntu package) - addressed in versions 0.27.2-8ubuntu2.2, 0.27.3-3ubuntu0.2, 0.27.3-3ubuntu1.1
exiv2 - addressed in versions 0.27.3-6.fc33, 0.27.3-6.fc34
exiv2 (Red Hat package) - update to 0.27.4-5.el8
exiv2 - update to 0.27.5-2
exiv2-libs - update to 0.27.5-2
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=1946314
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2XQT5F5IINTDYDAFGVGQZ7PMMLG7I5ZZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2A5GMJEXQ5Q76JK6F6VKK5JYCLVFGKN/