#VU60721 Path traversal in ExifTool - CVE-2022-23935
Published: February 20, 2022 / Updated: February 12, 2023
ExifTool
ExifTool
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the file names within lib/Image/ExifTool.pm. A remote attacker can pass a specially crafted file name to the application and read arbitrary files on the system.