Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation, causing excessive memory growth. In applications that parse attacker-supplied images, this may lead to denial of service through memory exhaustion.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
CWE-1284
Vulnerability Title
ExifReader 安全漏洞
Vulnerability Description
ExifReader是Mattias Wallander个人开发者的一款图像元数据提取库。 ExifReader 4.39.0之前版本存在安全漏洞,该漏洞源于处理ICC mluc标签时边界验证不足,可能导致内存耗尽拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A