CVE-2024-39695
Exiv2 has an out-of-bounds read in AsfVideo::streamProperties
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. The bug is fixed in version v0.28.3.
Exiv2 es una utilidad de línea de comandos y una librería de C++ para leer, escribir, eliminar y modificar los metadatos de archivos de imagen. Se encontró una lectura fuera de los límites en la versión v0.28.2 de Exiv2. La vulnerabilidad está en el analizador del formato de vídeo ASF, que era una característica nueva en la versión 0.28.0. La lectura fuera de los límites se activa cuando se utiliza Exiv2 para leer los metadatos de un archivo de vídeo creado. El error se solucionó en la versión v0.28.3.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-06-27 CVE Reserved
- 2024-07-08 CVE Published
- 2024-07-10 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/Exiv2/exiv2/commit/3a28346db5ae1735a8728fe3491b0aecc1dbf387 | 2024-07-09 | |
https://github.com/Exiv2/exiv2/pull/3006 | 2024-07-09 |
URL | Date | SRC |
---|---|---|
https://github.com/Exiv2/exiv2/security/advisories/GHSA-38rv-8x93-pvrh | 2024-07-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Exiv2 Search vendor "Exiv2" | Exiv2 Search vendor "Exiv2" for product "Exiv2" | >= 0.28.0 < 0.28.3 Search vendor "Exiv2" for product "Exiv2" and version " >= 0.28.0 < 0.28.3" | - |
Affected
|