Logo
vulnerabilityCVE-2026-3102
Name
CVE-2026-3102
Source
NVD ( link)Debian ( link)
Description
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 13.50 is capable of addressing this issue. Patch name: e9609a9bcc0d32bd252a709a562fb822d6dd86f7. Upgrading the affected component is recommended.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
exiftool
False Positive

Vulnerability Ratings#


2.1
CVSSv4
6.3
CVSSv31
8.8
CVSSv31
7.5
CVSSv2
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
yocto
master
13.59
Not Affected