CVE-2025-54080
Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-125
Lectura fuera de límites
Fecha de publicación:
29/08/2025
Última modificación:
02/09/2025
Descripción
*** Pendiente de traducción *** Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions 0.28.5 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. The bug is fixed in version 0.28.6.
Impacto
Puntuación base 4.0
1.80
Gravedad 4.0
BAJA
Puntuación base 3.x
5.50
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*:* | 0.28.6 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



