Impact
ExifReader is a JavaScript library that parses EXIF metadata. In versions preceding 4.40.1, the load functions can forward HEIC or AVIF data to the ISO‑BMFF parser in src\/image-header-iso-bmff.js, where findMetaBox() and parseBox() accept an eight‑byte box header without verifying that the required fields remain in the DataView. This flaw allows an attacker to supply crafted box structures, such as a valid ftyp box followed by an empty free or unknown box, which can trigger an unchecked full‑box version read, or a truncated extended‑size box that causes getBoxLength() and hasEmptyHighBits() to read absent size fields. The resulting RangeError propagates out of the parsing routine and can abort an application request or worker if the error is not defensively caught, leading to a denial‑of‑service condition. The issue is resolved in ExifReader version 4.40.1.
Affected Systems
The vulnerability affects the ExifReader library from the vendor mattiasw, impacting all releases prior to version 4.40.1. Any project that loads EXIF data via ExifReader.load() or its asynchronous file and URL loaders when processing HEIC or AVIF images is potentially exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1 % shows extremely low probability of targeted exploitation, and the flaw is not listed in CISA’s KEV catalogue. Attackers would need to supply a specially crafted HEIC or AVIF file containing malformed boxes to trigger the error. The likely vector is a web application or client‑side code that loads user‑supplied images via ExifReader.load() or its asynchronous loaders. If the application does not catch the resulting RangeError, the exception can terminate the request or worker, causing a temporary loss of service for the affected user or session.
OpenCVE Enrichment
Github GHSA