diff --git a/crates/kamadak-exif/RUSTSEC-0000-0000.md b/crates/kamadak-exif/RUSTSEC-0000-0000.md new file mode 100644 index 0000000..ea7d055 --- /dev/null +++ b/crates/kamadak-exif/RUSTSEC-0000-0000.md @@ -0,0 +1,22 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "kamadak-exif" +date = "2021-01-04" +url = "https://github.com/kamadak/exif-rs/commit/1b05eab57e484cd7d576d4357b9cda7fdc57df8c" +categories = ["denial-of-service"] +cvss = "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" +keywords = ["untrusted-data", "dos"] +aliases = ["CVE-2021-21235", "GHSA-px9g-8hgv-jvg2"] + +[affected] +functions = { "kamadak_exif::Reader::read_from_container" = [">= 0.5.2, < 0.5.3"] } + +[versions] +patched = [">= 0.5.3"] +unaffected = ["< 0.5.2"] + +``` +# kamadak-exif DoS with untrusted PNG data + +Attacker crafted data can cause a infinite loop leading to DoS if used with untrusted data. \ No newline at end of file