Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30763
HistoryJun 01, 2021 - 7:48 a.m.

Information Disclosure

2021-06-0107:48:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
exiv2
vulnerability
metadata
crafted image
information disclosure
exploit

EPSS

0.001

Percentile

32.7%

Exiv2 is vulnerable to information disclosure. The read of uninitialized memory is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to leak a few bytes of stack memory, if they can trick the victim into running Exiv2 on a crafted image file.