← Voltar para CVEs
CVE-2026-27631
MEDIUM5.3
Descricao
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an uncaught exception was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. Due to an integer overflow, the code attempts to create a huge std::vector, which causes Exiv2 to crash with an uncaught exception. This issue has been patched in version 0.28.8.
Detalhes CVE
Pontuacao CVSS v3.15.3
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado3/2/2026
Ultima modificacao3/5/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
exiv2:exiv2
Fraquezas (CWE)
CWE-248
Referencias
https://github.com/Exiv2/exiv2/commit/659db316eef745899a778a1e0b760a971d1b69df(security-advisories@github.com)
https://github.com/Exiv2/exiv2/issues/3513(security-advisories@github.com)
https://github.com/Exiv2/exiv2/pull/3514(security-advisories@github.com)
https://github.com/Exiv2/exiv2/security/advisories/GHSA-p2pw-7935-c73j(security-advisories@github.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.