• CVE-2024-39695

发布时间: 2024年7月12日

修改时间: 2024年8月19日

概要

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.

CVSS v3 指标

NVD openEuler
Confidentiality Low None
Attack Vector Network Network
CVSS评分 6.5 5.3
Attack Complexity Low Low
Privileges Required None None
Scope Unchanged Unchanged
Integrity None None
User Interaction None None
Availability Low Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-4802 exiv2 security update 2025年2月17日

影响产品

产品 状态
V6 exiv2 Fixed