CVE-2025-54080

EUVD-2025-26207
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions 0.28.5 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. The bug is fixed in version 0.28.6.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 3.81%
Affected Products (NVD)
VendorProductVersion
exiv2exiv2
𝑥
< 0.28.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
exiv2
bookworm
no-dsa
bullseye
postponed
bullseye (security)
vulnerable
forky
0.28.8+dfsg-1
fixed
sid
0.28.8+dfsg-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
exiv2
bionic
Fixed 0.25-3.1ubuntu0.18.04.11+esm1
released
focal
Fixed 0.27.2-8ubuntu2.7+esm1
released
jammy
Fixed 0.27.5-3ubuntu1.1
released
noble
Fixed 0.27.6-1ubuntu0.1
released
plucky
ignored
questing
Fixed 0.28.5+dfsg-1ubuntu0.1
released
resolute
not-affected
xenial
Fixed 0.25-2.1ubuntu16.04.7+esm5
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libexiv2-12
suse enterprise sap 12 SP5
0.23-12.26.1
fixed
suse enterprise server 12 SP5
0.23-12.26.1
fixed
libexiv2-devel
suse enterprise sap 12 SP5
0.23-12.26.1
fixed
suse enterprise server 12 SP5
0.23-12.26.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
exiv2
Amazon Linux 2
0:0.27.0-4.amzn2.0.6
fixed
Amazon Linux 2023
0:0.28.5-129.amzn2023
fixed
exiv2-debuginfo
Amazon Linux 2
0:0.27.0-4.amzn2.0.6
fixed
Amazon Linux 2023
0:0.28.5-129.amzn2023
fixed
exiv2-debugsource
Amazon Linux 2023
0:0.28.5-129.amzn2023
fixed
exiv2-devel
Amazon Linux 2
0:0.27.0-4.amzn2.0.6
fixed
Amazon Linux 2023
0:0.28.5-129.amzn2023
fixed
exiv2-doc
Amazon Linux 2
0:0.27.0-4.amzn2.0.6
fixed
Amazon Linux 2023
0:0.28.5-129.amzn2023
fixed
exiv2-libs
Amazon Linux 2
0:0.27.0-4.amzn2.0.6
fixed
Amazon Linux 2023
0:0.28.5-129.amzn2023
fixed
exiv2-libs-debuginfo
Amazon Linux 2023
0:0.28.5-129.amzn2023
fixed