CVE-2021-22204

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
GitLabCNA
6.8 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
exiftool_projectexiftool
7.44 ≤
𝑥
< 12.24
debiandebian_linux
9.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libimage-exiftool-perl
bullseye
12.16+dfsg-2
fixed
bookworm
12.57+dfsg-1
fixed
sid
13.00+dfsg-1
fixed
trixie
13.00+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libimage-exiftool-perl
jammy
not-affected
impish
not-affected
hirsute
Fixed 12.16+dfsg-1ubuntu0.1
released
groovy
Fixed 12.05-1ubuntu0.1
released
focal
Fixed 11.88-1ubuntu0.1
released
bionic
Fixed 10.80-1ubuntu0.1
released
xenial
Fixed 10.10-1ubuntu0.1~esm1
released
trusty
dne
References