Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size. When asynchronous parsing is enabled, a crafted PNG file containing a highly compressed zTXt chunk can cause ExifReader to materialize a disproportionately large Comment value in memory.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
对高度压缩数据的处理不恰当(数据放大攻击)
Vulnerability Title
ExifReader 安全漏洞
Vulnerability Description
ExifReader是Mattias Wallander个人开发者的一款图像元数据提取库。 ExifReader 4.39.0之前版本存在安全漏洞,该漏洞源于解压PNG zTXt元数据时未限制输出大小,可能导致内存中生成过大的Comment值。
CVSS Information
N/A
Vulnerability Type
N/A