← All CVEs

CVE-2021-22204

medium · 6.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-17Remediation due 2021-12-01

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

6.8
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2021-04-23
Published

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
exiftool_projectexiftool>= 7.44, < 12.24
debiandebian_linux9.0
debiandebian_linux10.0
fedoraprojectfedora32
fedoraprojectfedora33
fedoraprojectfedora34

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-22204