{"id":"CVE-2023-44398","summary":"Out-of-bounds write in exiv2","details":"Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, `BmffImage::brotliUncompress`, is new in v0.28.0, so earlier versions of Exiv2 are _not_ affected. The out-of-bounds write is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to gain code execution, if they can trick the victim into running Exiv2 on a crafted image file. This bug is fixed in version v0.28.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.","aliases":["GHSA-hrw9-ggg3-3r4r","PYSEC-2023-233"],"modified":"2026-08-12T03:30:32.365322447Z","published":"2023-11-06T17:30:54.394Z","related":["openSUSE-SU-2024:13403-1"],"database_specific":{"cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/44xxx/CVE-2023-44398.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/44xxx/CVE-2023-44398.json"},{"type":"ADVISORY","url":"https://github.com/Exiv2/exiv2/security/advisories/GHSA-hrw9-ggg3-3r4r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-44398"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202312-06"},{"type":"FIX","url":"https://github.com/Exiv2/exiv2/commit/e884a0955359107f4031c74a07406df7e99929a5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/exiv2/exiv2","events":[{"introduced":"931a40a746f5678dcc4625b06a2eb25fa4f00b34"},{"fixed":"e884a0955359107f4031c74a07406df7e99929a5"}],"database_specific":{"extracted_events":[{"introduced":"0.28.0"},{"last_affected":"0.28.0"}],"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:exiv2:exiv2:0.28.0:*:*:*:*:*:*:*"}}],"versions":["0.28.0","= 0.28.0","v0.28.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-44398.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}