yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2021-31292
Component Overview
Vulnerability Overview
Name
CVE-2021-31292
Source
NVD (
link
)
Debian (
link
)
Description
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
CWEs
CWE-190
Published Date
Jul 26, 2021
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/Exiv2/exiv2/issues/1530
Exploit
https://lists.debian.org/debian-lts-announce/2021/08/msg00028.html
Mailing List
https://www.debian.org/security/2021/dsa-4958
Third Party Advisory
https://github.com/Exiv2/exiv2/issues/1530
Exploit
https://lists.debian.org/debian-lts-announce/2021/08/msg00028.html
Mailing List
https://www.debian.org/security/2021/dsa-4958
Third Party Advisory
Analysis
#
Affected Component
Analysis
exiv2
Patched
Vulnerability Ratings
#
7.5
CVSSv31
5
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
exiv2
buildroot
2025.02.x
0.28.8
Not Affected
exiv2
buildroot
master
0.28.8
Not Affected
exiv2
yocto
master
0.28.8
Not Affected
exiv2
yocto
scarthgap
0.28.3
Not Affected
Resolved with patches
#
exiv2 (yocto:kirkstone)
#
Title
Author
Resolve
1
Fix integer overflow.
Kevin Backhouse <kevinbackhouse@github.com>
CVE-2021-29458
CVE-2021-31292