Hacker News
Read post

ExifTool CVE-2021-22204 - Arbitrary Code Execution

The post discusses a bug in ExifTool that allows for arbitrary code execution. The author discovered the bug while examining a bug bounty program and noticed they were using an older version of ExifTool. The bug involves the use of the 'eval' function in Perl, which can be abused to execute code. The post also mentions potential formats that can be used to trigger the bug, such as DjVu and TIFF.

    #perl
Jan 27, 2024•16m read time•From devcraft.io
Post cover image
Table of contents
BackgroundThe BugAdditional FormatsBonus FormatsReferences
6 Impressions
Hacker News's image
Hacker News

Hacker News is a community-driven platform for sharing and discussing technology news, startups, and...

17.4K Followers

•

141.8K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard