CVE-2021-22204
ExifTool Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
25Exploited in Wild
YesDecision
Descriptions
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
Una neutralización inapropiada de los datos del usuario en el formato de archivo DjVu en ExifTool versiones 7.44 y posteriores, permite una ejecución de código arbitrario cuando se analiza la imagen maliciosa
A vulnerability was discovered in libimage-exiftool-perl, a library and program to read and write meta information in multimedia files, which may result in execution of arbitrary code if a malformed DjVu file is processed.
Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2021-01-05 CVE Reserved
- 2021-04-23 CVE Published
- 2021-05-12 First Exploit
- 2021-11-17 Exploited in Wild
- 2021-12-01 KEV Due Date
- 2025-02-06 CVE Updated
- 2025-06-28 EPSS Updated
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (34)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2021/05/09/1 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2021/05/10/5 | Mailing List |
|
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22204.json | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2021/05/msg00018.html | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://github.com/exiftool/exiftool/commit/cf0f4e7dcd024ca99615bfd1102a841a25dde031#diff-fa0d652d10dbcd246e6b1df16c1e992931d3bb717a7e36157596b76bdadb3800 | 2024-07-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Exiftool Project Search vendor "Exiftool Project" | Exiftool Search vendor "Exiftool Project" for product "Exiftool" | >= 7.44 < 12.24 Search vendor "Exiftool Project" for product "Exiftool" and version " >= 7.44 < 12.24" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 32 Search vendor "Fedoraproject" for product "Fedora" and version "32" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 33 Search vendor "Fedoraproject" for product "Fedora" and version "33" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
|