PublicDateAtUSN: 2021-08-09 18:15:00 UTC Candidate: CVE-2021-34334 PublicDate: 2021-08-09 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34334 https://github.com/Exiv2/exiv2/security/advisories/GHSA-hqjh-hpv8-8r9p https://github.com/Exiv2/exiv2/pull/1766 https://ubuntu.com/security/notices/USN-5043-1 Description: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.5. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: leosilva CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_exiv2: upstream: https://github.com/Exiv2/exiv2/pull/1766/commits/a35a2fde2dcd940a756feaeb027375b390bd8a06 (regression test) upstream: https://github.com/Exiv2/exiv2/pull/1766/commits/97c4880882d87aee77809b4b6e8fb4a5558e4ca2 (fix) upstream: https://github.com/Exiv2/exiv2/pull/1766/commits/1b204d9b19efcff1acad56737d6483a393e24832 (extra fix) upstream: https://github.com/Exiv2/exiv2/pull/1766/commits/ee8af718983469af5a86f041b58a5f52b1cbad76 (extra fix) upstream: https://github.com/Exiv2/exiv2/pull/1766/commits/e74d8accc431d9064589bad6cf8f17c30229523d (extra fix) upstream_exiv2: needs-triage trusty_exiv2: ignored (out of standard support) trusty/esm_exiv2: DNE xenial_exiv2: ignored (out of standard support) esm-infra/xenial_exiv2: released (0.25-2.1ubuntu16.04.7+esm4) bionic_exiv2: released (0.25-3.1ubuntu0.18.04.11) focal_exiv2: released (0.27.2-8ubuntu2.6) hirsute_exiv2: released (0.27.3-3ubuntu1.5) impish_exiv2: released (0.27.3-3ubuntu4) jammy_exiv2: released (0.27.3-3ubuntu4) devel_exiv2: released (0.27.3-3ubuntu4)