Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. The out-of-bounds read is at a 4GB offset, which usually causes Exiv2 to crash. This issue has been patched in version 0.28.8.
CVSS Details
- CVSS 4.0 Base Score: 2.7 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade exiv2 | Aug 31, 2026 | Mar 2, 2026 |
| Amazon Linux Ami 2 | — | Upgrade exiv2-develUpgrade exiv2-libsUpgrade exiv2-docUpgrade exiv2Upgrade exiv2-debuginfo | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade exiv2-debugsourceUpgrade exiv2-develUpgrade exiv2-libs-debuginfoUpgrade exiv2-debuginfoUpgrade exiv2-libsUpgrade exiv2Upgrade exiv2-doc | Mar 27, 2026 | Mar 2, 2026 |
| Gentoo Linux | — | Upgrade media-gfx/exiv2. | Mar 10, 2026 | Mar 9, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Mar 2, 2026 |
| Ubuntu | — | Upgrade exiv2Upgrade exiv2 (Ubuntu Pro) | Mar 19, 2026 | Mar 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub