CVE-2022-24613

Description

metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use metadata-extractor library.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.213

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-24613,CVE-2022-24614 are fixed in Drew-Noakes-metadata-extractor 2.18.0Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.59Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.60Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.61Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.3Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.4Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.5Windows
Vulnerabilities CVE-2022-24613,CVE-2022-24614 are fixed in Drew-Noakes-metadata-extractor for Linux 2.18.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234