Heap-based buffer overflow in Exiv2 - CVE-2021-29457

 

Heap-based buffer overflow in Exiv2 - CVE-2021-29457

Published: August 17, 2021


Vulnerability identifier: #VU55920
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29457
CWE-ID:
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A remote attacker can trick the victim top open a specially crafted image, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Note that this bug is only triggered when _writing_ the metadata, which is a less frequently used Exiv2 operation than _reading_ the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as `insert`.


Affected software

Exiv2
Gentoo Linux
Arch Linux
Red Hat CodeReady Linux Builder for x86_64
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
openEuler
Fedora
exiv2 (Debian package)
exiv2-debuginfo
exiv2-debugsource
libexiv2-12
libexiv2-12-debuginfo
libexiv2-devel
libexiv2-14 (Ubuntu package)
compat-exiv2-026
exiv2-help
exiv2-devel
exiv2
libexiv2-27 (Ubuntu package)
exiv2-libs
exiv2 (Red Hat package)
media-gfx/exiv2

How to mitigate CVE-2021-29457

Install updates from vendor's website.

Exiv2 - update to 0.27.4
exiv2 (Debian package) - update to 0.25-4+deb10u2
exiv2-debuginfo - update to 0.23-12.18.1
exiv2-debugsource - update to 0.23-12.18.1
libexiv2-12 - update to 0.23-12.18.1
libexiv2-12-debuginfo - update to 0.23-12.18.1
libexiv2-devel - update to 0.23-12.18.1
libexiv2-14 (Ubuntu package) - addressed in versions 0.25-3.1ubuntu0.18.04.7, 0.25-3.1ubuntu0.18.04.11
compat-exiv2-026 - update to 0.26-4
exiv2-help - update to 0.26-25
exiv2-debugsource - update to 0.26-25
exiv2-debuginfo - update to 0.26-25
exiv2-devel - update to 0.26-25
exiv2 - update to 0.26-25
libexiv2-27 (Ubuntu package) - addressed in versions 0.27.2-8ubuntu2.2, 0.27.3-3ubuntu0.2, 0.27.3-3ubuntu1.1
exiv2 - update to 0.27.3-3
exiv2-libs - update to 0.27.3-3
exiv2 - addressed in versions 0.27.3-6.fc33, 0.27.3-6.fc34
exiv2 (Red Hat package) - update to 0.27.4-5.el8
media-gfx/exiv2 - update to 0.28.1

External References

Related Security Bulletins