HIGH7.5
PYSEC-2021-877
Details
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/exiv2
Introduced in:
0No fixed version published yet for exiv2 (pip). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/Exiv2/exiv2/issues/1530[FIX]
- https://www.debian.org/security/2021/dsa-4958[ADVISORY]
- https://lists.debian.org/debian-lts-announce/2021/08/msg00028.html[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FMDT4PJB7P43WSOM3TRQIY3J33BAFVVE/[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UYGDELIFFJWKUU7SO3QATCIXCZJERGAC/[WEB]