VDB
CVE-2021-22204
CVE-2021-22204
PUBLISHED
KEV
CVSS 6.800000190734863 MEDIUM
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
EPSS 99.98% · 100.0th percentile
Risk Scores
CVSS 3.1
6.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
EPSS Score
99.98%
100.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:20.04:LTS | libimage-exiftool-perl | 0, 11.65-1, 11.74-1 |
| Ubuntu:Pro:16.04:LTS | libimage-exiftool-perl | 10.09-1, 10.10-1, 10.02-1 |
| Ubuntu:18.04:LTS | libimage-exiftool-perl | 10.65-1, 10.67-1, 10.64-1 |
Timeline
- CVE Published
- Apr 27, 2021 EPSS Score
- May 11, 2021 PoC Published
- May 12, 2021 PoC Published
- May 12, 2021 EPSS Score
- May 12, 2021 VulnCheck XDB Entry
- May 16, 2021 EPSS Score
- Sep 1, 2021 EPSS Score
- Sep 30, 2021 VulnCheck KEV Exploitation
- Oct 1, 2021 PoC Published
- Nov 3, 2021 PoC Published
- Nov 4, 2021 PoC Published
References
- https://ubuntu.com/security/CVE-2021-22204 third-party-advisory
- https://bugs.launchpad.net/bugs/1925985 third-party-advisory
- https://github.com/exiftool/exiftool/commit/cf0f4e7dcd024ca99615bfd1102a841a25dde031#diff-fa0d652d10dbcd246e6b1df16c1e992931d3bb717a7e36157596b76bdadb3800 third-party-advisory
- https://hackerone.com/reports/1154542 third-party-advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22204.json third-party-advisory
- https://ubuntu.com/security/notices/USN-4987-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2021-22204 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog third-party-advisory
- https://ubuntu.com/security/notices/USN-4987-2 vendor-advisory