Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-29464

26
FAUCET Score

CVE-2021-29464 describes a heap buffer overflow in Exiv2 versions v0.27.3 and earlier, a utility and library for image metadata manipulation. This vulnerability affects Exiv2 and related Fedora packages. It carries a CVSS score of 7.8 (High), indicating that an attacker could achieve code execution by tricking a user into processing a specially crafted image file with Exiv2, specifically during a metadata write operation. While the attack complexity is low, user interaction is required, and the impact on confidentiality, integrity, and availability is high. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.27.4CPE matchmatch criteria
cpe:2.3:a:exiv2:exiv2:*:*:*:*:*:*:*:*
33CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.3LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.50%
Probability of exploitation in next 30 days
EPSS Percentile
71.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0150 is in the 70th percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 17009-16823Fixed in: 0.27.5-1
microsoftpatch availablevia msrc
Product: cbl2 exiv2 0.27.5-1 on CBL Mariner 2.0Fixed in: 0.27.5-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 0.27.5-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 0.27.5-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: exiv2-0:0.27.4-5.el8
View patch

Vendor Advisories (3)

microsoft2022-Jan/CVE-2021-29464

CVE-2021-29464

Jan 11, 2022
redhatCVE-2021-29464Moderate

exiv2: Heap-based buffer overflow in Exiv2::Jp2Image::encodeJp2Header

May 1, 2021
microsoft2021-Apr/CVE-2021-29464Important

Heap buffer overflow in Exiv2::Jp2Image::encodeJp2Header

Apr 13, 2021

References

github.com / Exiv2/exiv2/commit/f9308839198aca5e68a65194f151a1de92398f54
PatchThird Party Advisory
github.com / Exiv2/exiv2/security/advisories/GHSA-jgm9-5fw5-pw9p
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/K3HKXR6JOVKMBE4HY4FDXNVZGNCQG6T3
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NDMZTVQAZSMLPTDVDYLBHAAF7I5QXVYQ
security.gentoo.org / glsa/202312-06