{"id":"CVE-2021-22204","details":"Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image","modified":"2026-08-07T11:48:35.045066080Z","published":"2021-04-23T18:15:08.127Z","related":["openSUSE-SU-2021:0707-1"],"database_specific":{"unresolved_ranges":[{"vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"}],"source":"CPE_STRING"},{"cpes":["cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"32"},{"last_affected":"32"},{"introduced":"33"},{"last_affected":"33"},{"introduced":"34"},{"last_affected":"34"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"}]},"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22204"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/05/09/1"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/05/10/5"},{"type":"ADVISORY","url":"https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22204.json"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/05/msg00018.html"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDKDLJLBTBBR66OOPXSXCG2PQRM5KCZL/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F6UOBPU3LSHAPRRJNISNVXZ5DSUIALLV/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U4RF6PJCJ6NQOVJJJF6HN6BORUQVIXY6/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4910"},{"type":"REPORT","url":"https://hackerone.com/reports/1154542"},{"type":"FIX","url":"https://github.com/exiftool/exiftool/commit/cf0f4e7dcd024ca99615bfd1102a841a25dde031#diff-fa0d652d10dbcd246e6b1df16c1e992931d3bb717a7e36157596b76bdadb3800"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/162558/ExifTool-DjVu-ANT-Perl-Injection.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Command-Injection.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/167038/ExifTool-12.23-Arbitrary-Code-Execution.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/exiftool/exiftool","events":[{"introduced":"0"},{"fixed":"cf0f4e7dcd024ca99615bfd1102a841a25dde031"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:exiftool_project:exiftool:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.44"},{"fixed":"12.24"}]}}],"versions":["12.23","12.22","12.21","12.20","12.19","12.18","12.17","12.16","12.15","12.14","12.13","12.12","12.11","12.10","12.09","12.08","12.07","12.06","12.05","12.04","12.03","12.02","12.01","12.00","11.99","11.98","11.97","11.96","11.95","11.94","11.93","11.92","11.91","11.90","11.89","11.88","11.87","11.86","11.85","11.84","11.83","11.82","11.81","11.80","11.79","11.78","11.77","11.76","11.75","11.74","11.73","11.72","11.71","11.70","11.69","11.68","11.67","11.66","11.65","11.64","11.63","11.62","11.61","11.60","11.59","11.58","11.57","11.56","11.55","11.54","11.53","11.52","11.51","11.50","11.49","11.48","11.47","11.46","11.45","11.44","11.43","11.42","11.41","11.40","11.39","11.38","11.37","11.36","11.35","11.34","11.33","11.32","11.31","11.30","11.29","11.28","11.27","11.26","11.25","11.24","11.23","11.22","11.21","11.20","11.19","11.18","11.16","11.15","11.14","11.13","11.12","11.11","11.10","11.09","11.08","11.07","11.06","11.05","11.04","11.03","11.02","11.01","11.00","10.99","10.98","10.97","10.96","10.95","10.94","10.93","10.92","10.91","10.90","10.89","10.88","10.87","10.86","10.85","10.84","10.83","10.82","10.81","10.78","10.77","10.76","10.75","10.74","10.73","10.72","10.71","10.69","10.68","10.67","10.66","10.65","10.64","10.63","10.62","10.61","10.60","10.59","10.58","10.57","10.56","10.55","10.54","10.53","10.52","10.51","10.50","10.49","10.48","10.47","10.46","10.45","10.44","10.43","10.42","10.41","10.40","10.39","10.38","10.37","10.36","10.35","10.34","10.33","10.32","10.31","10.30","10.29","10.28","10.27","10.26","10.25","10.24","10.23","10.22","10.21","10.20","10.19","10.18","10.17","10.16","10.15","10.14","10.13","10.12","10.11","10.10","10.09","10.08","10.07","10.06","10.05","10.04","10.03","10.02","10.01","10.00","9.99","9.98","9.97","9.96","9.95","9.94","9.93","9.92","9.91","9.90","9.89","9.88","9.87","9.86","9.85","9.84","9.83","9.82","9.81","9.80","9.79","9.78","9.77","9.76","9.75","9.74","9.73","9.72","9.71"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22204.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}