VDB

DEBIAN-CVE-2022-24613

DEBIAN-CVE-2022-24613 PUBLISHED CVSS 5.5 MEDIUM

metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use metadata-extractor library.

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:11libmetadata-extractor-java2.11.0-1, 0, 2.11.0-1
Debian:12libmetadata-extractor-java0, 2.11.0-1, 0
Debian:13libmetadata-extractor-java2.11.0-1, 0, 0
Debian:14libmetadata-extractor-java0, 2.11.0-1, 0

Timeline

  • Feb 24, 2022 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›