4.3
CVSSv2

CVE-2021-27815

Published: 14/04/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and previous versions allows malicious users to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libexif project exif

fedoraproject fedora 32

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #1018814 exif: CVE-2021-27815: NULL pointer dereference with strncpy() in exif/actionsc Package: exif; Maintainer for exif is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Source for exif is src:exif (PTS, buildd, popcon) Reported by: Aron Xu <aron@debianorg> ...
A NULL pointer deference in the "actionsc" library of libexif version 0622 allows attackers to cause a denial of service (DoS) by opening a malicious JPEG file, causing the application to crash ...