VDB

CVE-2021-22204

CVE-2021-22204 PUBLISHED KEV

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

EPSS 92.83% · 99.8th percentile

Risk Scores

EPSS Score
92.83%
99.8th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlibimage-exiftool-perl0, 11.65-1, 11.74-1
Ubuntu:Pro:16.04:LTSlibimage-exiftool-perl10.09-1, 10.10-1, 10.02-1
Ubuntu:18.04:LTSlibimage-exiftool-perl10.65-1, 10.67-1, 10.64-1

Timeline

  • CVE Published
  • Apr 27, 2021 EPSS Score
  • May 11, 2021 PoC Published
  • May 12, 2021 PoC Published
  • May 12, 2021 EPSS Score
  • May 16, 2021 EPSS Score
  • Aug 31, 2021 EPSS Score
  • Oct 1, 2021 PoC Published
  • Nov 3, 2021 PoC Published
  • Nov 4, 2021 PoC Published
  • Nov 5, 2021 EPSS Score
  • Nov 17, 2021 CISA KEV Added
Open in Interactive Console →
$ Console Community · 100/wk Open console ›