Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-27815
HistoryApr 14, 2021 - 12:00 a.m.

CVE-2021-27815

2021-04-1400:00:00
ubuntu.com
ubuntu.com
11
cve-2021-27815
null pointer deference
exif v0.6.22
xml formatted exif data
jpeg file
denial of service
application crash
unix

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

54.6%

NULL Pointer Deference in the exif command line tool, when printing out XML
formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause
a Denial of Service (DoS) by uploading a malicious JPEG file, causing the
application to crash.

OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchexif< anyUNKNOWN
ubuntu24.04noarchexif< anyUNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

54.6%