{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu18.04els/vex/2021/cve-2021-32617-els_os-ubuntu18_04els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-28T16:55:34Z",
      "generator": {
        "date": "2026-08-28T16:55:34Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2021-32617-ELS_OS-UBUNTU18.04ELS",
      "initial_release_date": "2021-05-17T18:15:00Z",
      "revision_history": [
        {
          "date": "2021-05-17T18:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-28T16:55:34Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2021-32617"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 18.04",
                "product": {
                  "name": "Ubuntu 18.04",
                  "product_id": "Ubuntu-18",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
                "product": {
                  "name": "exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
                  "product_id": "exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/exiv2@0.25-3.1ubuntu0.18.04.11?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
                "product": {
                  "name": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
                  "product_id": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libexiv2-14@0.25-3.1ubuntu0.18.04.11?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
                "product": {
                  "name": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
                  "product_id": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libexiv2-dev@0.25-3.1ubuntu0.18.04.11?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all",
                "product": {
                  "name": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all",
                  "product_id": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libexiv2-doc@0.25-3.1ubuntu0.18.04.11?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                "product": {
                  "name": "exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                  "product_id": "exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/exiv2@0.25-3.1ubuntu0.18.04.11%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                "product": {
                  "name": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                  "product_id": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libexiv2-14@0.25-3.1ubuntu0.18.04.11%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                "product": {
                  "name": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                  "product_id": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libexiv2-dev@0.25-3.1ubuntu0.18.04.11%2Btuxcare.els2?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
                "product": {
                  "name": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
                  "product_id": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libexiv2-doc@0.25-3.1ubuntu0.18.04.11%2Btuxcare.els2?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64"
        },
        "product_reference": "exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64"
        },
        "product_reference": "exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all"
        },
        "product_reference": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all"
        },
        "product_reference": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64"
        },
        "product_reference": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64"
        },
        "product_reference": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64"
        },
        "product_reference": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64"
        },
        "product_reference": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-32617",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. The bug is fixed in version v0.27.4. Note that this bug is only triggered when _writing_ the metadata, which is a less frequently used Exiv2 operation than _reading_ the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as `rm`.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
          "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
          "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
          "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
          "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
          "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
          "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
          "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2021-32617"
        },
        {
          "category": "external",
          "summary": "https://github.com/Exiv2/exiv2/pull/1657",
          "url": "https://github.com/Exiv2/exiv2/pull/1657"
        },
        {
          "category": "external",
          "summary": "https://github.com/Exiv2/exiv2/security/advisories/GHSA-w8mv-g8qq-36mj",
          "url": "https://github.com/Exiv2/exiv2/security/advisories/GHSA-w8mv-g8qq-36mj"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5I3RRZUGSBIUYZ5TIHLN55PKMAWCSJ5G/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5I3RRZUGSBIUYZ5TIHLN55PKMAWCSJ5G/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M2BPQNJKTRIDINTVJ22QMMTIZEPHVKXK/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M2BPQNJKTRIDINTVJ22QMMTIZEPHVKXK/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQAKFIQHW2AS3AGSJM42ABOA6CWIJBGM/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQAKFIQHW2AS3AGSJM42ABOA6CWIJBGM/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZ5SGWHK64TB7ADRSVBGHEPDFN5CSOO3/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TZ5SGWHK64TB7ADRSVBGHEPDFN5CSOO3/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202312-06",
          "url": "https://security.gentoo.org/glsa/202312-06"
        }
      ],
      "release_date": "2021-05-17T18:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-18T14:37:10.902952Z",
          "details": "CVE-2021-32617 is a local, user‑interaction denial‑of‑service in Exiv2 that is only triggered during metadata write operations (e.g., rm/modify actions) on crafted images; simple reads are unaffected. In enterprise server/VM contexts, exposure requires an application to explicitly invoke Exiv2 to write metadata to untrusted files, and even then the impact is limited to process/resource exhaustion with no confidentiality or integrity effect. Given these constrained preconditions and DoS‑only outcome, this can be safely deprioritized where Exiv2 isn’t used to write metadata on untrusted input.",
          "product_ids": [
            "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
            "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
            "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
            "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
            "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
            "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
            "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
            "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "accessComplexity": "MEDIUM",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
            "version": "2.0"
          },
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
            "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
            "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
            "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
            "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
            "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
            "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
            "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}