
Cloud Vulnerability DB
A community-led vulnerabilities database
RUSTSEC-2021-0143 is a vulnerability in the exif-rs crate that could cause an infinite loop when reading PNG files. The issue was discovered in version 0.5.2 and fixed in version 0.5.3 of the crate (GitHub Commit).
The vulnerability was caused by a missing check for empty buffers in the discard_exact() function when reading PNG files. This could lead to an infinite loop condition when processing certain PNG files. The fix involved adding an explicit check for empty buffers and returning an UnexpectedEOF error in such cases (GitHub Commit).
When exploited, this vulnerability could cause applications using the affected versions of exif-rs to enter an infinite loop while processing PNG files, potentially leading to resource exhaustion and denial of service conditions.
The vulnerability can be triggered by providing a specially crafted PNG file to applications using the affected versions of the exif-rs crate.
Users should upgrade to exif-rs version 0.5.3 or later which contains the fix for this vulnerability. The fix adds proper error handling for unexpected EOF conditions during buffer reading operations (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."