Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an uncaught exception was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. Due to an integer overflow, the code attempts to create a huge std::vector, which causes Exiv2 to crash with an uncaught exception. This issue has been patched in version 0.28.8.
CVSS Details
- CVSS 4.0 Base Score: 2.7 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade exiv2 | Aug 31, 2026 | Mar 2, 2026 |
| Amazon Linux Ami 2 | — | Upgrade exiv2-libsUpgrade exiv2Upgrade exiv2-docUpgrade exiv2-develUpgrade exiv2-debuginfo | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade exiv2Upgrade exiv2-docUpgrade exiv2-debuginfoUpgrade exiv2-libsUpgrade exiv2-debugsourceUpgrade exiv2-develUpgrade exiv2-libs-debuginfo | Mar 27, 2026 | Mar 2, 2026 |
| Gentoo Linux | — | Upgrade media-gfx/exiv2. | Mar 10, 2026 | Mar 9, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Mar 2, 2026 |
| Ubuntu | — | Upgrade exiv2 (Ubuntu Pro)Upgrade exiv2 | Mar 19, 2026 | Mar 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub