HIGH

CVE-2021-22204

Debian Debian Linux 2021-04-23 CVSS v3.1
CVSS
7.8
KEV

Description

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

Summary dbcve.org

ExifTool versions 7.44 and above contain a command injection vulnerability in its DjVu image file parser. The tool fails to properly sanitize user-supplied data embedded in DjVu files, allowing attackers to achieve arbitrary code execution by tricking users into processing specially crafted malicious images.

Mitigation

Update ExifTool to the vendor-patched version when available, or downgrade to a version prior to 7.44 if immediate patching is not feasible. Until patched, avoid processing untrusted DjVu files with ExifTool and consider running ExifTool in an isolated sandbox or container for legitimate use cases.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

99.98%
Probability of exploitation in next 30 days
100th percentile

References

http://packetstormsecurity.com/files/162558/ExifTool-DjVu-ANT-Perl-Injection.html Exploit, Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html Exploit, Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html Exploit, Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/167038/ExifTool-12.23-Arbitrary-Code-Execution.html Exploit, Third Party Advisory, VDB Entry http://www.openwall.com/lists/oss-security/2021/05/09/1 Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2021/05/10/5 Mailing List, Third Party Advisory https://github.com/exiftool/exiftool/commit/cf0f4e7dcd024ca99615bfd1102a841a25dde031#diff-fa0d652d10dbcd246e6b1df16c1e992931d3bb717a7e36157596b76bdadb3800 Patch https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22204.json Third Party Advisory https://hackerone.com/reports/1154542 Exploit, Issue Tracking, Third Party Advisory https://lists.debian.org/debian-lts-announce/2021/05/msg00018.html Mailing List, Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDKDLJLBTBBR66OOPXSXCG2PQRM5KCZL/ Release Notes https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F6UOBPU3LSHAPRRJNISNVXZ5DSUIALLV/ Release Notes https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U4RF6PJCJ6NQOVJJJF6HN6BORUQVIXY6/ Release Notes https://www.debian.org/security/2021/dsa-4910 Mailing List, Third Party Advisory https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22204 US Government Resource
View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE