CVE-2021-27815
Summary
| CVE | CVE-2021-27815 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-14 14:15:00 UTC |
| Updated | 2023-11-07 03:32:00 UTC |
| Description | NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 33 Update: exif-0.6.22-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: exif-0.6.22-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| actually return empty stringand not 'em,pty string' as expected · libexif/exif@eb84b0e · GitHub |
MISC |
github.com |
|
| NullPointer in actions.c:701:7 · Issue #4 · libexif/exif · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 32 Update: exif-0.6.22-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: exif-0.6.22-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: exif-0.6.22-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: exif-0.6.22-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| added empty strign check, which would lead to NULL ptr deref/crash in… · libexif/exif@f6334d9 · GitHub |
MISC |
github.com |
|
| exif: Denial of Service (GLSA 202210-28) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184286 Debian Security Update for exif (CVE-2021-27815)
- 281172 Fedora Security Update for exif (FEDORA-2021-477809f45f)
- 281173 Fedora Security Update for exif (FEDORA-2021-04f7b000fa)
- 281174 Fedora Security Update for exif (FEDORA-2021-b2bd2b1d13)
- 296061 Oracle Solaris 11.4 Support Repository Update (SRU) 42.113.1 Missing (CPUJAN2022)
- 710655 Gentoo Linux exif Denial of Service Vulnerability (GLSA 202210-28)