CVE-2021-31292

Related Vulnerabilities: CVE-2021-31292  

A flaw was found in exiv2. A integer wraparound in the CrwMap:encode0x1810 function leads to memcpy call with a very large size allowing an attacker, who can provide a malicious image, to crash an application which uses the exiv2 library. The highest threat from this vulnerability is to service availability.

Description

A flaw was found in exiv2. A integer wraparound in the CrwMap:encode0x1810 function leads to memcpy call with a very large size allowing an attacker, who can provide a malicious image, to crash an application which uses the exiv2 library. The highest threat from this vulnerability is to service availability.

Additional Information

  • Bugzilla 1990330: CVE-2021-31292 exiv2: Integer overflow in CrwMap:encode0x1810 leading to heap-based buffer overflow and DoS
  • CWE-190->CWE-125: Integer Overflow or Wraparound leads to Out-of-bounds Read
  • FAQ: Frequently asked questions about CVE-2021-31292