CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
Percentile
33.8%
Exiv2 is a command-line utility and C++ library for reading, writing,
deleting, and modifying the metadata of image files. A floating point
exception (FPE) due to an integer divide by zero was found in Exiv2
versions v0.27.4 and earlier. The FPE is triggered when Exiv2 is used to
print the metadata of a crafted image file. An attacker could potentially
exploit the vulnerability to cause a denial of service, if they can trick
the victim into running Exiv2 on a crafted image file. Note that this bug
is only triggered when printing the interpreted (translated) data, which is
a less frequently used Exiv2 operation that requires an extra command line
option (-p t
or -P t
). The bug is fixed in version v0.27.5.
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
Percentile
33.8%