FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

p5-Image-ExifTool -- code injection via crafted media

Affected packages
p5-Image-ExifTool < 13.54
p5-Image-ExifTool-devel < 13.54

Details

VuXML ID bba381b5-b842-11f1-8205-107c614c014e
Discovery 2026-05-01
Entry 2026-09-24

ExifTool versions up to 13.53 contain a code injection flaw in the Process_mrld function of lib/Image/ExifTool/GM.pm, reached while parsing JPEG, QuickTime, MOV and MP4 files. When exiftool is invoked with the -ee (extract embedded) option on a crafted file, a local attacker with low privileges can inject code that runs in the Perl runtime context of the exiftool process.

The issue is fixed in ExifTool 13.54.

References

CVE Name CVE-2026-7580
URL https://github.com/advisories/GHSA-qjrf-c4wp-pgxx
URL https://nvd.nist.gov/vuln/detail/cve-2026-7580