Fiche vulnérabilité
CVE-2021-22204 : faille exploitée exiftool project exiftool (CVSS 7.8)
Description
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Exploitation active
- Oui, inscrite au catalogue CISA KEV
- Publication
- 23 avr. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- exiftool project exiftool
- debian debian linux
- fedoraproject fedora
Correctif et mesures
Apply updates per vendor instructions.
Références
- Fiche CVE-2021-22204 sur le NVD (NIST)
- packetstormsecurity.com/files/162558/ExifTool…
- packetstormsecurity.com/files/164768/GitLab…
- packetstormsecurity.com/files/164994/GitLab…
- packetstormsecurity.com/files/167038/ExifTool…
- openwall.com/lists/oss-security/2021/05/09/1
- openwall.com/lists/oss-security/2021/05/10/5
- github.com/exiftool/exiftool/commit/cf0f4e7dcd024ca99615b…
- gitlab.com/gitlab…
- hackerone.com/reports/1154542
- lists.debian.org/debian-lts-announce/2021/05/msg00018.html
- lists.fedoraproject.org/archives/list/package…
- lists.fedoraproject.org/archives/list/package…
- lists.fedoraproject.org/archives/list/package…
- debian.org/security/2021/dsa-4910
- cisa.gov/known-exploited-vulnerabilities-catalog