Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-service was found in Exiv2 version v0.28.1: an unbounded recursion can cause Exiv2 to crash by exhausting the stack. The vulnerable function, `QuickTimeVideo::multipleEntriesDecoder`, was new in v0.28.0, so Exiv2 versions before v0.28 are _not_ affected. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted video file. This bug is fixed in version v0.28.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 16 Oct 2024 20:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Exiv2 Exiv2 exiv2 | |
| CPEs | cpe:2.3:a:exiv2:exiv2:0.28.0:*:*:*:*:*:*:* cpe:2.3:a:exiv2:exiv2:0.28.1:*:*:*:*:*:*:* | |
| Vendors & Products | Exiv2 Exiv2 exiv2 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-02-12T22:11:13.693Z
Updated: 2024-08-01T23:36:21.619Z
Reserved: 2024-02-05T14:14:46.378Z
Link: CVE-2024-25112
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-01T23:36:21.619Z
 NVD
                        NVD
                    Status : Modified
Published: 2024-02-12T23:15:08.853
Modified: 2024-11-21T09:00:16.810
Link: CVE-2024-25112
 Redhat
                        Redhat
                     ReportizFlow
ReportizFlow