Bug#1135381: libimage-exiftool-perl: CVE-2026-7580

Salvatore Bonaccorso carnil at debian.org
Fri May 1 22:01:29 BST 2026


Source: libimage-exiftool-perl
Version: 13.50+dfsg-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>

Hi,

The following vulnerability was published for libimage-exiftool-perl.

CVE-2026-7580[0]:
| A vulnerability was detected in Exiftool up to 13.53. Impacted is
| the function Process_mrld of the file lib/Image/ExifTool/GM.pm of
| the component JPEG/QuickTime/MOV/MP4. The manipulation of the
| argument -ee results in code injection. Attacking locally is a
| requirement. Upgrading to version 13.54 is recommended to address
| this issue. The patch is identified as
| 5a8b6b6ead12b39e3f32f978a4efd0233facbb01. It is suggested to upgrade
| the affected component. The fix in the source code mentions: "[J]ust
| to be safe, probably never happen".


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-7580
    https://www.cve.org/CVERecord?id=CVE-2026-7580
[1] https://github.com/exiftool/exiftool/commit/5a8b6b6ead12b39e3f32f978a4efd0233facbb01

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the pkg-perl-maintainers mailing list