Impact
This vulnerability resides in the Metadata Handler of the pdeljanov Symphonia library and permits a local attacker to trigger a denial of service by manipulating metadata content. The flaw results in an application crash or resource exhaustion, without providing any other compromise.
Affected Systems
All releases of Symphonia up to and including version 0.6.0 are affected. The flaw resides in the Metadata Handler component, which is invoked when processing media files or other data that contains metadata.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low probability of exploitation, and the attacker must launch the attack locally. An exploit has been published, and it might be used against systems that can run code locally. The vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation.
OpenCVE Enrichment