INFSA-2025:7457: exiv2 security update
Information about definition
Identificator: INFSA-2025:7457
Type: security
Release date: 2025-07-15 19:29:56 UTC
Information about package
Exiv2 is a C++ library to access image metadata, supporting read and write access to the Exif, IPTC and XMP metadata, Exif MakerNote support, extract and delete methods for Exif thumbnails, classes to access Ifd, and support for various image formats.
Vulnerabilities description
- CVE-2025-26623
A heap overflow vulnerability was found in the Exiv2 library. In affected versions, the issue is triggered when Exiv2 is used to write metadata into a crafted image file. This could allow an attacker to execute code if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2025-26623
|
no information | 6.3 | no information |
Updated packages