Path traversal in ExifTool - CVE-2022-23935
Published: February 20, 2022 / Updated: February 12, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the file names within lib/Image/ExifTool.pm. A remote attacker can pass a specially crafted file name to the application and read arbitrary files on the system.
Affected software
Gentoo Linux
Fedora
perl-Image-ExifTool
media-libs/exiftool
How to mitigate CVE-2022-23935
perl-Image-ExifTool - addressed in versions 12.38-1.el7, 12.38-1.el8, 12.38-1.fc34, 12.38-1.fc35
media-libs/exiftool - update to 12.42
Links to Public Exploits and PoC-codes
- Exploit #8829 - CVE-2022-23935 (? Python Exploit for CVE-2022-23935) (February 12, 2023)
- Exploit #8800 - CVE-2022-23935 (CVE-2022-23935 exploit PoC exiftool version 12.37 written in python) (February 7, 2023)
- Exploit #8776 - CVE-2022-23935-PoC-Exploit (CVE-2022-23935 exploit PoC exiftool version 12.37) (January 29, 2023)