Skip to content

Out-of-bounds read in AsfVideo::streamProperties

Low
kevinbackhouse published GHSA-38rv-8x93-pvrh Jul 8, 2024

Package

No package listed

Affected versions

0.28.2

Patched versions

0.28.3

Description

Impact

An out-of-bounds read was found in Exiv2 version v0.28.2. The vulnerability is in the parser for the ASF video format, which was a new feature in v0.28.0 (see #2416), so Exiv2 versions before v0.28 are not affected. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file.

Patches

The bug is fixed in version v0.28.3. It is fixed by #3006.

For more information

Please see our security policy for information about Exiv2 security.

Credit

This bug was found by OSS-Fuzz.

Severity

Low

CVE ID

CVE-2024-39695

Weaknesses