VDB

CVE-2021-22204

CVE-2021-22204 PUBLISHED KEV CVSS 6.800000190734863 MEDIUM

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

EPSS 99.98% · 100.0th percentile

Risk Scores

CVSS 3.1
6.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
EPSS Score
99.98%
100.0th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlibimage-exiftool-perl0, 11.65-1, 11.74-1
Ubuntu:Pro:16.04:LTSlibimage-exiftool-perl10.09-1, 10.10-1, 10.02-1
Ubuntu:18.04:LTSlibimage-exiftool-perl10.65-1, 10.67-1, 10.64-1

Timeline

  • CVE Published
  • Apr 27, 2021 EPSS Score
  • May 11, 2021 PoC Published
  • May 12, 2021 PoC Published
  • May 12, 2021 EPSS Score
  • May 12, 2021 VulnCheck XDB Entry
  • May 16, 2021 EPSS Score
  • Sep 1, 2021 EPSS Score
  • Sep 30, 2021 VulnCheck KEV Exploitation
  • Oct 1, 2021 PoC Published
  • Nov 3, 2021 PoC Published
  • Nov 4, 2021 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›