CVE-2024-39695

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://github.com/Exiv2/exiv2/commit/3a28346db5ae1735a8728fe3491b0aecc1dbf387 - Patch () https://github.com/Exiv2/exiv2/commit/3a28346db5ae1735a8728fe3491b0aecc1dbf387 - Patch
References () https://github.com/Exiv2/exiv2/pull/3006 - Issue Tracking, Patch () https://github.com/Exiv2/exiv2/pull/3006 - Issue Tracking, Patch
References () https://github.com/Exiv2/exiv2/security/advisories/GHSA-38rv-8x93-pvrh - Vendor Advisory () https://github.com/Exiv2/exiv2/security/advisories/GHSA-38rv-8x93-pvrh - Vendor Advisory
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.3

09 Jul 2024, 14:47

Type Values Removed Values Added
CPE cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*:*
References () https://github.com/Exiv2/exiv2/commit/3a28346db5ae1735a8728fe3491b0aecc1dbf387 - () https://github.com/Exiv2/exiv2/commit/3a28346db5ae1735a8728fe3491b0aecc1dbf387 - Patch
References () https://github.com/Exiv2/exiv2/pull/3006 - () https://github.com/Exiv2/exiv2/pull/3006 - Issue Tracking, Patch
References () https://github.com/Exiv2/exiv2/security/advisories/GHSA-38rv-8x93-pvrh - () https://github.com/Exiv2/exiv2/security/advisories/GHSA-38rv-8x93-pvrh - Vendor Advisory
First Time Exiv2
Exiv2 exiv2
Summary
  • (es) Exiv2 es una utilidad de línea de comandos y una librería de C++ para leer, escribir, eliminar y modificar los metadatos de archivos de imagen. Se encontró una lectura fuera de los límites en la versión v0.28.2 de Exiv2. La vulnerabilidad está en el analizador del formato de vídeo ASF, que era una característica nueva en la versión 0.28.0. La lectura fuera de los límites se activa cuando se utiliza Exiv2 para leer los metadatos de un archivo de vídeo creado. El error se solucionó en la versión v0.28.3.
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5

08 Jul 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-08 16:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-39695

Mitre link : CVE-2024-39695

CVE.ORG link : CVE-2024-39695


JSON object : View

Products Affected

exiv2

  • exiv2
CWE
CWE-125

Out-of-bounds Read