kamadak-exif
Activity
- Latest release
- 1y ago
- Total releases
- 19
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- License
- BSD-2-Clause
- First release
- Dec 31, 2016
| Version | Released | |
|---|---|---|
0.6.1
unknown
|
0.6.1
unknown
Dependencies (1)
|
|
0.6.0
unknown
|
0.6.0
unknown
Dependencies (1)
|
|
0.5.5
unknown
|
0.5.5
unknown
Dependencies (1)
|
|
0.5.4
unknown
|
0.5.4
unknown
Dependencies (1)
|
|
0.5.3
unknown
|
0.5.3
unknown
Dependencies (1)
|
|
0.5.2
unknown
1 CVE
CVE-2021-21235
GHSA-px9g-8hgv-jvg2
RUSTSEC-2021-0143
Oct 06, 2022
kamadak-exif vulnerable to Infinite loop when parsing PNG files
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
ImpactReader::read_from_container can cause an infinite loop when a crafted PNG file is given. PatchesVersion 0.5.3 includes the fix. WorkaroundsNo workaround is available. Applications that do not pass files with the PNG signature to Reader::read_from_container are not affected. References
For more informationIf you have any questions or comments about this advisory:
Affected versions
0.5.2
Fixed in
0.5.3
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.5.2
unknown
Dependencies (1)
|
|
0.5.1
unknown
|
0.5.1
unknown
Dependencies (1)
|
|
0.5.0
unknown
|
0.5.0
unknown
Dependencies (1)
|
|
0.4.0
unknown
|
0.4.0
unknown
Dependencies (1)
|
|
0.3.1
unknown
|
0.3.1
unknown
|
|
0.3.0
unknown
|
0.3.0
unknown
|
|
0.2.3
unknown
|
0.2.3
unknown
|
|
0.2.2
unknown
|
0.2.2
unknown
|
|
0.2.1
unknown
|
0.2.1
unknown
|
|
0.2.0
unknown
|
0.2.0
unknown
|
|
0.1.3
unknown
|
0.1.3
unknown
|
|
0.1.2
unknown
|
0.1.2
unknown
|
|
0.1.1
unknown
|
0.1.1
unknown
|
|
0.1.0
unknown
|
0.1.0
unknown
|