Impact
TinyEXIF, a library for parsing EXIF metadata, contains a heap-based buffer over-read in the EntryParser::Fetch methods that can be triggered by a crafted SubjectArea length. This weak buffer may expose sensitive data and is classified as CWE-125, denoting unsafe read operations that can lead to information disclosure or application crashes.
Affected Systems
All builds of TinyEXIF before version 1.1.0 are affected, regardless of vendor implementation. The library is developed and maintained by cdcseacave. Any deployment that incorporates a pre‑1.1.0 release when parsing EXIF metadata from untrusted image files is vulnerable.
Risk and Exploitability
The CVSS score of 2.9 indicates a low severity, and the EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been documented. However, the over‑read can be reached through a specifically crafted SubjectArea field in EXIF metadata, which is typically embedded in image files. Therefore, the risk is modest but still relevant in environments that process untrusted images.
OpenCVE Enrichment