RubySec

Providing security resources for the Ruby community

GHSA-q95h-cqrv-8jv5 (exiftool_vendored): ExifTool vulnerable to arbitrary code execution

ADVISORIES

GEM

exiftool_vendored

SEVERITY

CVSS v3.x: 7.8 (High)

PATCHED VERSIONS

  • >= 12.25.0

DESCRIPTION

Impact

Arbitrary code execution can occur when running exiftool against files with hostile metadata payloads

Patches

ExifTool has already been patched in version 12.24. exiftool_vendored.rb, which vendors ExifTool, includes this patch in v12.25.0.

Workarounds

No

RELATED