7.5
CVSSv3

CVE-2019-20421

Published: 27/01/2020 Updated: 14/09/2021
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

It exists that Exiv2 incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

exiv2 exiv2 0.27.2

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.10

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Synopsis Moderate: exiv2 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for exiv2, gegl, gnome-color-manager, and libgexiv2 is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moder ...
Debian Bug report logs - #950183 exiv2: CVE-2019-20421 Package: src:exiv2; Maintainer for src:exiv2 is Debian KDE Extras Team <pkg-kde-extras@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 29 Jan 2020 21:09:01 UTC Severity: important Tags: fixed-upstream, security, upstream ...
Exiv2 could be made to crash if it opened a specially crafted image ...
Several vulnerabilities have been discovered in Exiv2, a C++ library and a command line utility to manage image metadata which could result in denial of service or the execution of arbitrary code if a malformed file is parsed For the stable distribution (buster), these problems have been fixed in version 025-4+deb10u2 We recommend that you upgra ...