CVE-2021-22204

EUVD-2021-9350
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
GitLabCNA
6.8 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
exiftool_projectexiftool
7.44 ≤
𝑥
< 12.24
debiandebian_linux
9.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libimage-exiftool-perl
bookworm
12.57+dfsg-1
fixed
bullseye
12.16+dfsg-2
fixed
sid
13.00+dfsg-1
fixed
trixie
13.00+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libimage-exiftool-perl
bionic
Fixed 10.80-1ubuntu0.1
released
focal
Fixed 11.88-1ubuntu0.1
released
groovy
Fixed 12.05-1ubuntu0.1
released
hirsute
Fixed 12.16+dfsg-1ubuntu0.1
released
impish
not-affected
jammy
not-affected
trusty
dne
xenial
Fixed 10.10-1ubuntu0.1~esm1
released
References