CVE-2021-3482

medium
Published 2021-11-09 ยท Modified 2021-11-09
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.5

Description

RHSA-2021:4173: exiv2 security, bug fix, and enhancement update (Moderate)

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description exiv2: Heap-based buffer overflow in Jp2Image::readMetadata() CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8exiv2-0:0.27.4-5.el8RHSA-2021:41732021-11-09T00:00:00Z Package state ProductPackageState Red Hat Enterprise Linux 6exiv2Out of support scope Red Hat Enterprise Linux 7exiv2Out ofโ€ฆ

Description

exiv2: Heap-based buffer overflow in Jp2Image::readMetadata()

CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8exiv2-0:0.27.4-5.el8RHSA-2021:41732021-11-09T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6exiv2Out of support scope
Red Hat Enterprise Linux 7exiv2Out of support scope
Red Hat Enterprise Linux 9exiv2Not affected

Apply commands

bash fix
Apply RHSA-2021:4173 for Red Hat Enterprise Linux 8
yum update -y exiv2
# or:
dnf upgrade -y exiv2

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 9Not affected

OS impact

OSVersionStatusFixed in
arch archfixed0.27.4-1
debian debianbookwormfixed0.27.5-1
debian debianbullseyefixed0.27.3-3+deb11u2
debian debianforkyfixed0.27.5-1
debian debiansidfixed0.27.5-1
debian debiantrixiefixed0.27.5-1
rockylinux rocky8fixed
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.