Out-of-bounds read in Exiv2 - CVE-2021-37620
Published: November 28, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when processing metadata of a crafted image file. A remote attacker can pass a specially crafted image file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Ubuntu
openEuler
Fedora
exiv2-debugsource
libexiv2-12
libexiv2-12-debuginfo
libexiv2-devel
exiv2-debuginfo
libexiv2-14 (Ubuntu package)
libexiv2-27 (Ubuntu package)
exiv2 (Ubuntu package)
mingw-exiv2
exiv2-help
exiv2
exiv2-devel
media-gfx/exiv2
How to mitigate CVE-2021-37620
exiv2-debugsource - update to 0.23-12.18.1
libexiv2-12 - update to 0.23-12.18.1
libexiv2-12-debuginfo - update to 0.23-12.18.1
libexiv2-devel - update to 0.23-12.18.1
exiv2-debuginfo - update to 0.23-12.18.1
libexiv2-14 (Ubuntu package) - update to 0.25-3.1ubuntu0.18.04.11
libexiv2-27 (Ubuntu package) - addressed in versions 0.27.2-8ubuntu2.6, 0.27.2-8ubuntu2.7, 0.27.3-3ubuntu1.5, 0.27.3-3ubuntu1.6, 0.27.3-3ubuntu4.1
exiv2 (Ubuntu package) - addressed in versions 0.27.2-8ubuntu2.7, 0.27.3-3ubuntu1.6, 0.27.3-3ubuntu4.1
mingw-exiv2 - addressed in versions 0.27.4-3.fc33, 0.27.4-3.fc34
exiv2-help - addressed in versions 0.27.5-1, 0.27.5-2
exiv2 - addressed in versions 0.27.5-1, 0.27.5-2
exiv2-devel - addressed in versions 0.27.5-1, 0.27.5-2
exiv2-debugsource - addressed in versions 0.27.5-1, 0.27.5-2
exiv2-debuginfo - addressed in versions 0.27.5-1, 0.27.5-2
media-gfx/exiv2 - update to 0.28.1
External References
- https://github.com/Exiv2/exiv2/pull/1769
- https://github.com/Exiv2/exiv2/security/advisories/GHSA-v5g7-46xf-h728
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FMDT4PJB7P43WSOM3TRQIY3J33BAFVVE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UYGDELIFFJWKUU7SO3QATCIXCZJERGAC/