An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust available CPU resources.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libexif | Jun 11, 2020 | Feb 20, 2019 |
| Debian | — | Upgrade libexif | May 19, 2020 | Feb 20, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libexif | Apr 2, 2019 | Feb 20, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libexif | Mar 27, 2019 | Feb 20, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libexif | Apr 3, 2019 | Feb 20, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libexif | Jul 26, 2019 | Feb 20, 2019 |
| Oracle Solaris | — | Upgrade image/library/libexif to version 0.6.21-11.4.16.0.1.3.0 on Solaris 11.4 | Dec 18, 2019 | Feb 20, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 20, 2019 |
| Suse | — | Upgrade libexif-32bitUpgrade libexif-develUpgrade libexifUpgrade libexif12Upgrade libexif-devel-32bitUpgrade libexif12-32bit | Mar 2, 2020 | Feb 20, 2019 |
| Ubuntu | — | Upgrade libexif12 (Ubuntu Pro)Upgrade libexif12 | Jun 24, 2020 | Feb 20, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub