exiv2

condav0.28.8

Exiv2 is a Cross-platform C++ library and a command line utility to manage image metadata

License GPL-2.0-or-later13 versions1 maintainers0 deps870 weekly dl
Exiv2/exiv2
62
/ 100
Health
update required

[email protected] has vulnerabilities — update to latest

Update to >= e884a0955359107f4031c74a07406df7e99929a5 to fix known vulnerabilities

  • 1 high severity vulnerabilities
Health breakdown0 – 100
20/25
maintenance
3/20
popularity
20/25
security
12/15
maturity
7/15
community
Vulnerabilities
1
1 high
Advisories (1)
SeverityIDSummaryFixed in
highCVE-2023-44398Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, `BmffImage::brotliUncompress`, is new in v0.28.0, so earlier versions of Exiv2 are _not_ affected. The out-of-bounds write is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to gain code execution, if they cane884a0955359107f4031c74a07406df7e99929a5

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/conda/exiv2

First published · 2020-07-01 23:42:50.370000+00:00

Last updated · 2026-03-01 23:09:53.182000+00:00