UBUNTU-CVE-2021-22204
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-22204
UBUNTU-CVE-2021-22204
Summary:
Details: Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
References: https://ubuntu.com/security/CVE-2021-22204, https://bugs.launchpad.net/bugs/1925985, https://github.com/exiftool/exiftool/commit/cf0f4e7dcd024ca99615bfd1102a841a25dde031#diff-fa0d652d10dbcd246e6b1df16c1e992931d3bb717a7e36157596b76bdadb3800, https://hackerone.com/reports/1154542, https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22204.json, https://ubuntu.com/security/notices/USN-4987-1, https://www.cve.org/CVERecord?id=CVE-2021-22204, https://www.cisa.gov/known-exploited-vulnerabilities-catalog, https://ubuntu.com/security/notices/USN-4987-2
Affected packages
Package
Name: libimage-exiftool-perl
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
