Aller au contenu

Fiche vulnérabilité

CVE-2021-22204 : faille exploitée exiftool project exiftool (CVSS 7.8)

Description

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Oui, inscrite au catalogue CISA KEV
Publication
23 avr. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • exiftool project exiftool
  • debian debian linux
  • fedoraproject fedora

Correctif et mesures

Apply updates per vendor instructions.

Références

Rechercher une autre vulnérabilité dans la base CVE