INFSA-2025:7457: exiv2 security update

Information about definition

Identificator: INFSA-2025:7457

Type: security

Release date: 2025-07-15 19:29:56 UTC

Information about package

Exiv2 is a C++ library to access image metadata, supporting read and write access to the Exif, IPTC and XMP metadata, Exif MakerNote support, extract and delete methods for Exif thumbnails, classes to access Ifd, and support for various image formats.

Vulnerabilities description

  • CVE-2025-26623

    A heap overflow vulnerability was found in the Exiv2 library. In affected versions, the issue is triggered when Exiv2 is used to write metadata into a crafted image file. This could allow an attacker to execute code if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 6.3 no information
Critical, important, moderate, low

Updated packages