CVE-2022-24614
24.02.2022, 15:15
When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library.Enginsight
Vendor | Product | Version |
---|---|---|
metadata-extractor_project | metadata-extractor | 𝑥 < 2.16.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases