VDB
Sign up
MEDIUM6.5

GHSA-px9g-8hgv-jvg2

kamadak-exif vulnerable to Infinite loop when parsing PNG files

Details

### Impact Reader::read_from_container can cause an infinite loop when a crafted PNG file is given.

### Patches Version 0.5.3 includes the fix.

### Workarounds No workaround is available. Applications that do not pass files with the PNG signature to Reader::read_from_container are not affected.

### References * <https://github.com/kamadak/exif-rs/security/advisories/GHSA-px9g-8hgv-jvg2> * <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21235>

### For more information If you have any questions or comments about this advisory: * Open an issue in [github.com/kamadak/exif-rs](https://github.com/kamadak/exif-rs)

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/kamadak-exif
Introduced in: 0.5.2Fixed in: 0.5.3

Upgrade kamadak-exif to 0.5.3 or newer (ecosystem crates.io).

References