NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.
{
"unresolved_ranges": [
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"
],
"vendor_product": "fedoraproject:fedora",
"extracted_events": [
{
"introduced": "32"
},
{
"last_affected": "32"
},
{
"introduced": "33"
},
{
"last_affected": "33"
},
{
"introduced": "34"
},
{
"last_affected": "34"
}
]
}
]
}{
"cpe": "cpe:2.3:a:libexif_project:exif:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.6.22"
}
]
}[
{
"digest": {
"length": 826.0,
"function_hash": "117739525872714467810242060778568890977"
},
"signature_version": "v1",
"source": "https://github.com/libexif/exif/commit/eb84b0e3c5f2a86013b6fcfb800d187896a648fa",
"signature_type": "Function",
"target": {
"function": "escape_xml",
"file": "exif/actions.c"
},
"id": "CVE-2021-27815-32de5894",
"deprecated": false
},
{
"digest": {
"length": 774.0,
"function_hash": "66487071761578745178268823097657667458"
},
"signature_version": "v1",
"source": "https://github.com/libexif/exif/commit/f6334d9d32437ef13dc902f0a88a2be0063d9d1c",
"signature_type": "Function",
"target": {
"function": "escape_xml",
"file": "exif/actions.c"
},
"id": "CVE-2021-27815-5a7bcf89",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"56429957118893573836594359231792757542",
"236708506390338073920272238376695567027",
"251815281604461825816962047897251030965"
]
},
"signature_version": "v1",
"source": "https://github.com/libexif/exif/commit/f6334d9d32437ef13dc902f0a88a2be0063d9d1c",
"signature_type": "Line",
"target": {
"file": "exif/actions.c"
},
"id": "CVE-2021-27815-d8c64ba2",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"267985955826095369399255340329894694665",
"206567539733347984706140851524349779254",
"161934927561592451764293787085084039009",
"166523331223495064149312083299725894127"
]
},
"signature_version": "v1",
"source": "https://github.com/libexif/exif/commit/eb84b0e3c5f2a86013b6fcfb800d187896a648fa",
"signature_type": "Line",
"target": {
"file": "exif/actions.c"
},
"id": "CVE-2021-27815-e50fe298",
"deprecated": false
}
]
"2026-07-09T00:13:23Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-27815.json"