NA

CVE-2024-24826

Published: 12/02/2024 Updated: 13/02/2024

Vulnerability Summary

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.1. The vulnerable function, `QuickTimeVideo::NikonTagsDecoder`, was new in v0.28.0, so Exiv2 versions before v0.28 are _not_ affected. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. In most cases this out of bounds read will result in a crash. This bug is fixed in version v0.28.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Vendor Advisories

Debian Bug report logs - #1070392 exiv2: CVE-2024-24826 CVE-2024-25112 Package: src:exiv2; Maintainer for src:exiv2 is Debian KDE Extras Team <pkg-kde-extras@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sat, 4 May 2024 18:39:02 UTC Severity: normal Tags: security, upstream Found ...
Description<!---->A flaw was found in the Exiv2 command-line utility The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video fileA flaw was found in the Exiv2 command-line utility The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file ...