Skip to content

Out-of-bounds write in BmffImage::brotliUncompress

High
kevinbackhouse published GHSA-hrw9-ggg3-3r4r Nov 5, 2023

Package

No package listed

Affected versions

0.28.0

Patched versions

0.28.1

Description

Impact

An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, BmffImage::brotliUncompress, is new in v0.28.0, so earlier versions of Exiv2 are not affected. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds write is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to gain code execution, if they can trick the victim into running Exiv2 on a crafted image file.

Patches

The bug is fixed in version v0.28.1.

For more information

Please see our security policy for information about Exiv2 security.

Credit

This bug was found by OSS-Fuzz.

Severity

High

CVE ID

CVE-2023-44398

Weaknesses