Description
When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0819 | When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library. |
Github GHSA |
GHSA-4v6p-cxf9-98rf | Allocation of Resources Without Limits or Throttling in metadata-extractor |
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T04:13:56.973Z
Reserved: 2022-02-07T00:00:00.000Z
Link: CVE-2022-24614
No data.
Status : Analyzed
Published: 2022-02-24T15:15:29.750
Modified: 2025-09-12T19:46:21.530
Link: CVE-2022-24614
OpenCVE Enrichment
No data.
EUVD
Github GHSA