Package: libimage-exiftool-perl / 12.16+dfsg-2

Metadata

Package Version Patches format
libimage-exiftool-perl 12.16+dfsg-2 3.0 (quilt)

Patch series

view the series file
Patch File delta Description
CVE 2021 22204.patch | (download)

lib/Image/ExifTool/DjVu.pm | 9 5 + 4 - 0 !
1 file changed, 5 insertions(+), 4 deletions(-)

 fix 'eval injection".
 CVE-2021-22204: Improper neutralization of user data in the DjVu file
 format in ExifTool versions 7.44 and up allows arbitrary code execution
 when parsing the malicious image