OESA-2024-1054
Dashboard / Vulnerabilities / OESA-2024-1054
OESA-2024-1054
Summary: metadata-extractor2 security update
Details: Metadata Extractor is a straightforward Java library for reading metadata from image files. Security Fix(es): metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use metadata-extractor library.(CVE-2022-24613) When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library.(CVE-2022-24614)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1054, https://nvd.nist.gov/vuln/detail/CVE-2022-24613, https://nvd.nist.gov/vuln/detail/CVE-2022-24614
Affected packages
Package
Name: metadata-extractor2
Purl: pkg:rpm/openEuler/metadata-extractor2&distro=openEuler-22.03-LTS-SP3
Affected ranges
Type: ECOSYSTEM
Events:
