CVE-2026-3102

NameCVE-2026-3102
DescriptionA vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 13.50 is capable of addressing this issue. Patch name: e9609a9bcc0d32bd252a709a562fb822d6dd86f7. Upgrading the affected component is recommended.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libimage-exiftool-perl (PTS)bullseye12.16+dfsg-2fixed
bookworm12.57+dfsg-1fixed
trixie13.25+dfsg-1fixed
forky, sid13.50+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libimage-exiftool-perlsource(unstable)(not affected)

Notes

- libimage-exiftool-perl <not-affected> (Only affects Image::ExifTool when run on MacOS)

Search for package or bug name: Reporting problems