kamadak-exif vulnerable to Infinite loop when parsing PNG files
Description
Published by the National Vulnerability Database
Jan 6, 2021
Published to the GitHub Advisory Database
Oct 6, 2022
Reviewed
Oct 6, 2022
Last updated
Feb 2, 2023
Impact
Reader::read_from_container can cause an infinite loop when a crafted PNG file is given.
Patches
Version 0.5.3 includes the fix.
Workarounds
No workaround is available.
Applications that do not pass files with the PNG signature to Reader::read_from_container are not affected.
References
For more information
If you have any questions or comments about this advisory:
References