Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Vulnerability Description
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was found in Exiv2 version 0.28.5: a quadratic algorithm in the ICC profile parsing code in jpegBase::readMetadata() can cause Exiv2 to run for a long time. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted jpg image file. The bug is fixed in version 0.28.6.
CVSS Information
N/A
Vulnerability Type
算法复杂性
Vulnerability Title
Exiv2 安全漏洞
Vulnerability Description
Exiv2是Andreas Huggel个人开发者的一套用于管理图像元数据的C++库和命令行应用程序。该产品提供了读取和写入EXIF、IPTC和XMP等多种格式图像元数据的功能。 Exiv2 0.28.5版本存在安全漏洞,该漏洞源于ICC配置文件解析存在二次算法问题,可能导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A