Executive brief
ExifTool fails to properly neutralize user data within the DjVu file format, leading to arbitrary code execution. An attacker can exploit this by providing a specially crafted malicious image for parsing.
Affected products
- ExifTool ExifTool 7.44 and up
Timeline
- 2021-04-13: patched: GitHub commit cf0f4e7dcd024ca99615bfd1102a841a25dde031 fixes the issue.
- 2021-11-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-17: disclosed