Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.4. Note that this bug is only triggered when _writing_ the metadata, which is a less frequently used Exiv2 operation than _reading_ the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as `rm`.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade exiv2-libsUpgrade exiv2-develUpgrade exiv2Upgrade exiv2-doc | May 4, 2022 | May 17, 2021 |
| Alpine Linux | — | Upgrade exiv2 | Aug 22, 2024 | May 17, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 17, 2021 |
| Centos_linux | — | Upgrade exiv2-libsUpgrade exiv2Upgrade exiv2-debuginfoUpgrade exiv2-libs-debuginfoUpgrade exiv2-debugsource | Nov 10, 2021 | May 17, 2021 |
| Debian | — | Upgrade exiv2 | Jul 30, 2024 | May 17, 2021 |
| Freebsd | — | Upgrade exiv2 | Nov 4, 2022 | Jun 30, 2021 |
| Gentoo Linux | — | Upgrade media-gfx/exiv2. | Dec 27, 2023 | May 17, 2021 |
| Huawei Euleros 2_0_sp2 | — | Upgrade exiv2-libs | Sep 16, 2021 | May 17, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade exiv2-libs | Oct 26, 2021 | May 17, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade exiv2-libs | Sep 29, 2021 | May 17, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade exiv2-libsUpgrade exiv2 | Aug 10, 2021 | May 17, 2021 |
| Redhat_linux | — | Upgrade exiv2-debugsourceUpgrade exiv2-docUpgrade exiv2-develUpgrade exiv2-debuginfoUpgrade exiv2Upgrade exiv2-libsUpgrade exiv2-libs-debuginfoNo solution exists | Nov 10, 2021 | May 17, 2021 |
| Rocky_linux | — | Upgrade exiv2-debuginfoUpgrade exiv2-libs-debuginfoUpgrade exiv2-libsUpgrade exiv2-develUpgrade exiv2Upgrade exiv2-debugsource | Mar 12, 2024 | May 17, 2021 |
| Suse | — | Upgrade libexiv2-27-32bitUpgrade libexiv2-develUpgrade libexiv2-26-32bitUpgrade exiv2Upgrade libexiv2-12Upgrade exiv2-langUpgrade libexiv2-docUpgrade libexiv2-xmp-staticUpgrade libexiv2-27Upgrade libexiv2-26 | Oct 26, 2022 | May 17, 2021 |
| Ubuntu | — | Upgrade libexiv2-14 (Ubuntu Pro)Upgrade libexiv2-27Upgrade exiv2 (Ubuntu Pro)Upgrade libexiv2-14Upgrade exiv2 | May 26, 2021 | May 17, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub