{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu18.04els/vex/2021/cve-2021-37621-els_os-ubuntu18_04els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-28T16:55:34Z",
      "generator": {
        "date": "2026-08-28T16:55:34Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2021-37621-ELS_OS-UBUNTU18.04ELS",
      "initial_release_date": "2021-08-09T19:15:00Z",
      "revision_history": [
        {
          "date": "2021-08-09T19:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-28T16:55:34Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2021-37621"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 18.04",
                "product": {
                  "name": "Ubuntu 18.04",
                  "product_id": "Ubuntu-18",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
                "product": {
                  "name": "exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
                  "product_id": "exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/exiv2@0.25-3.1ubuntu0.18.04.11?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
                "product": {
                  "name": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
                  "product_id": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libexiv2-14@0.25-3.1ubuntu0.18.04.11?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
                "product": {
                  "name": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
                  "product_id": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libexiv2-dev@0.25-3.1ubuntu0.18.04.11?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all",
                "product": {
                  "name": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all",
                  "product_id": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libexiv2-doc@0.25-3.1ubuntu0.18.04.11?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                "product": {
                  "name": "exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                  "product_id": "exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/exiv2@0.25-3.1ubuntu0.18.04.11%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                "product": {
                  "name": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                  "product_id": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libexiv2-14@0.25-3.1ubuntu0.18.04.11%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                "product": {
                  "name": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                  "product_id": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libexiv2-dev@0.25-3.1ubuntu0.18.04.11%2Btuxcare.els2?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
                "product": {
                  "name": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
                  "product_id": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libexiv2-doc@0.25-3.1ubuntu0.18.04.11%2Btuxcare.els2?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64"
        },
        "product_reference": "exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64"
        },
        "product_reference": "exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all"
        },
        "product_reference": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all"
        },
        "product_reference": "libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64"
        },
        "product_reference": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64"
        },
        "product_reference": "libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64"
        },
        "product_reference": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64"
        },
        "product_reference": "libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-37621",
      "cwe": {
        "id": "CWE-835",
        "name": "Loop with Unreachable Exit Condition ('Infinite Loop')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when printing the image ICC profile, which is a less frequently used Exiv2 operation that requires an extra command line option (`-p C`). The bug is fixed in version v0.27.5.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
          "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
          "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
          "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
          "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
          "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
          "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
          "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2021-37621"
        },
        {
          "category": "external",
          "summary": "https://github.com/Exiv2/exiv2/pull/1778",
          "url": "https://github.com/Exiv2/exiv2/pull/1778"
        },
        {
          "category": "external",
          "summary": "https://github.com/Exiv2/exiv2/security/advisories/GHSA-m479-7frc-gqqg",
          "url": "https://github.com/Exiv2/exiv2/security/advisories/GHSA-m479-7frc-gqqg"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/01/msg00004.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/01/msg00004.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FMDT4PJB7P43WSOM3TRQIY3J33BAFVVE/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FMDT4PJB7P43WSOM3TRQIY3J33BAFVVE/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UYGDELIFFJWKUU7SO3QATCIXCZJERGAC/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UYGDELIFFJWKUU7SO3QATCIXCZJERGAC/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202312-06",
          "url": "https://security.gentoo.org/glsa/202312-06"
        }
      ],
      "release_date": "2021-08-09T19:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-18T14:37:00.685755Z",
          "details": "Exploitation requires a local user to explicitly run exiv2 with the non‑default “-p C” option on a crafted image to print its ICC profile, so the vulnerable code path isn’t exercised during ordinary metadata operations or via network exposure. The result is only a process-level denial of service (infinite loop) with no confidentiality or integrity impact and no privilege escalation. Given the narrow trigger and limited effect, this can be safely deprioritized in managed enterprise VM/server environments.",
          "product_ids": [
            "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
            "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
            "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
            "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
            "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
            "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
            "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
            "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "accessComplexity": "MEDIUM",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
            "version": "2.0"
          },
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
            "Ubuntu-18:exiv2-0:0.25-3.1ubuntu0.18.04.11.amd64",
            "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
            "Ubuntu-18:libexiv2-14-0:0.25-3.1ubuntu0.18.04.11.amd64",
            "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.amd64",
            "Ubuntu-18:libexiv2-dev-0:0.25-3.1ubuntu0.18.04.11.amd64",
            "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11+tuxcare.els2.all",
            "Ubuntu-18:libexiv2-doc-0:0.25-3.1ubuntu0.18.04.11.all"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}