4.3
CVSSv2

CVE-2021-21235

Published: 06/01/2021 Updated: 19/10/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

kamadak-exif is an exif parsing library written in pure Rust. In kamadak-exif version 0.5.2, there is an infinite loop in parsing crafted PNG files. Specifically, reader::read_from_container can cause an infinite loop when a crafted PNG file is given. This is fixed in version 0.5.3. No workaround is available. Applications that do not pass files with the PNG signature to Reader::read_from_container are not affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kamadak-exif project kamadak-exif 0.5.2

Vendor Advisories

Debian Bug report logs - #985309 CVE-2021-21235 Package: src:rust-kamadak-exif; Maintainer for src:rust-kamadak-exif is Debian Rust Maintainers <pkg-rust-maintainers@alioth-listsdebiannet>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 15 Mar 2021 19:06:02 UTC Severity: grave Tags: security Repl ...