Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MetadataExtractor 安全漏洞
Vulnerability Description
MetadataExtractor是一款用于从图像和视频文件中提取Exif、IPT、XMP和ICC等元数据的.NET库。 MetadataExtractor 存在安全漏洞,该漏洞源于当读取一个特别制作的JPEG文件时,可以使用2.16.0的元数据提取器来分配大量的内存,即使是非常小的输入,最终也会导致内存不足的错误。攻击者可利用该漏洞来对使用元数据提取器库的服务发起拒绝服务攻击。
CVSS Information
N/A
Vulnerability Type
N/A