Heap-based buffer overflow in Exiv2 - CVE-2021-29457
Published: August 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. A remote attacker can trick the victim top open a specially crafted image, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Note that this bug is only triggered when _writing_ the metadata, which is a less frequently used Exiv2 operation than _reading_ the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as `insert`.
Affected software
Gentoo Linux
Arch Linux
Red Hat CodeReady Linux Builder for x86_64
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
openEuler
Fedora
exiv2 (Debian package)
exiv2-debuginfo
exiv2-debugsource
libexiv2-12
libexiv2-12-debuginfo
libexiv2-devel
libexiv2-14 (Ubuntu package)
compat-exiv2-026
exiv2-help
exiv2-devel
exiv2
libexiv2-27 (Ubuntu package)
exiv2-libs
exiv2 (Red Hat package)
media-gfx/exiv2
How to mitigate CVE-2021-29457
exiv2 (Debian package) - update to 0.25-4+deb10u2
exiv2-debuginfo - update to 0.23-12.18.1
exiv2-debugsource - update to 0.23-12.18.1
libexiv2-12 - update to 0.23-12.18.1
libexiv2-12-debuginfo - update to 0.23-12.18.1
libexiv2-devel - update to 0.23-12.18.1
libexiv2-14 (Ubuntu package) - addressed in versions 0.25-3.1ubuntu0.18.04.7, 0.25-3.1ubuntu0.18.04.11
compat-exiv2-026 - update to 0.26-4
exiv2-help - update to 0.26-25
exiv2-debugsource - update to 0.26-25
exiv2-debuginfo - update to 0.26-25
exiv2-devel - update to 0.26-25
exiv2 - update to 0.26-25
libexiv2-27 (Ubuntu package) - addressed in versions 0.27.2-8ubuntu2.2, 0.27.3-3ubuntu0.2, 0.27.3-3ubuntu1.1
exiv2 - update to 0.27.3-3
exiv2-libs - update to 0.27.3-3
exiv2 - addressed in versions 0.27.3-6.fc33, 0.27.3-6.fc34
exiv2 (Red Hat package) - update to 0.27.4-5.el8
media-gfx/exiv2 - update to 0.28.1
External References
- https://github.com/Exiv2/exiv2/issues/1529
- https://github.com/Exiv2/exiv2/pull/1534
- https://github.com/Exiv2/exiv2/security/advisories/GHSA-v74w-h496-cgqm
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2XQT5F5IINTDYDAFGVGQZ7PMMLG7I5ZZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2A5GMJEXQ5Q76JK6F6VKK5JYCLVFGKN/
Related Security Bulletins
- Multiple vulnerabilities in Exiv2
- Debian update for exiv2
- SUSE update for exiv2
- Gentoo update for Exiv2
- openEuler 20.03 LTS SP1 update for exiv2
- Red Hat Enterprise Linux 8 update for exiv2
- Ubuntu update for exiv2
- Arch Linux update for exiv2
- Fedora 34 update for exiv2
- Fedora 33 update for exiv2
- Anolis OS update for compat-exiv2-026 (Anolis OS 8.4)
- Anolis OS update for exiv2 (Anolis OS 8.4)