CVE-2021-37620

Publication date 9 August 2021

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

5.5 · Medium

Score breakdown

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.5.

Read the notes from the security team

Status

Package Ubuntu Release Status
exiv2 22.04 LTS jammy
Fixed 0.27.3-3ubuntu4
21.10 impish
Fixed 0.27.3-3ubuntu4.1
21.04 hirsute
Fixed 0.27.3-3ubuntu1.6
20.04 LTS focal
Fixed 0.27.2-8ubuntu2.7
18.04 LTS bionic
Fixed 0.25-3.1ubuntu0.18.04.11
16.04 LTS xenial
14.04 LTS trusty Not in release

Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

Get Ubuntu Pro

Notes


leosilva

a regression was reported in (LP: #1941752) and fixed in USN-5043-2. It only affected focal, hirsute, impish and jammy.

Severity score breakdown

Parameter Value
Base score 5.5 · Medium
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

References

Related Ubuntu Security Notices (USN)

Other references