CVE-2021-22204 - log back

CVE-2021-22204 edited at 15 May 2021 07:33:34
References
+ https://devcraft.io/2021/05/04/exiftool-arbitrary-code-execution-cve-2021-22204.html
https://hackerone.com/reports/1154542
https://github.com/exiftool/exiftool/commit/cf0f4e7dcd024ca99615bfd1102a841a25dde031#diff-fa0d652d10dbcd246e6b1df16c1e992931d3bb717a7e36157596b76bdadb3800
CVE-2021-22204 edited at 25 Apr 2021 08:05:07
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 up to 12.23 allows arbitrary code execution when parsing the malicious image.
References
+ https://hackerone.com/reports/1154542
+ https://github.com/exiftool/exiftool/commit/cf0f4e7dcd024ca99615bfd1102a841a25dde031#diff-fa0d652d10dbcd246e6b1df16c1e992931d3bb717a7e36157596b76bdadb3800
Notes
CVE-2021-22204 created at 25 Apr 2021 08:03:35