Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-3482
HistoryApr 08, 2021 - 12:00 a.m.

CVE-2021-3482

2021-04-0800:00:00
ubuntu.com
ubuntu.com
13
exiv2
heap-based buffer overflow
jpg image
rawdata size
input validation
malicious exif data

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

EPSS

0.006

Percentile

77.9%

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1.
Improper input validation of the rawData.size property in
Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer
overflow via a crafted JPG image containing malicious EXIF data.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchexiv2< 0.25-3.1ubuntu0.18.04.7UNKNOWN
ubuntu20.04noarchexiv2< 0.27.2-8ubuntu2.2UNKNOWN
ubuntu20.10noarchexiv2< 0.27.3-3ubuntu0.2UNKNOWN
ubuntu21.04noarchexiv2< 0.27.3-3ubuntu1.1UNKNOWN
ubuntu21.10noarchexiv2< 0.27.3-3ubuntu2UNKNOWN
ubuntu22.04noarchexiv2< 0.27.3-3ubuntu2UNKNOWN
ubuntu16.04noarchexiv2< 0.25-2.1ubuntu16.04.7+esm1UNKNOWN

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

EPSS

0.006

Percentile

77.9%