[Bug 298826] graphics/p5-Image-ExifTool: Update to 13.55 (fixes CVE-2026-7580)
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298826] graphics/p5-Image-ExifTool: Update to 13.55 (fixes CVE-2026-7580)"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298826] graphics/p5-Image-ExifTool: Update to 13.55 (fixes CVE-2026-7580)"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298826] graphics/p5-Image-ExifTool: Update to 13.55 (fixes CVE-2026-7580)"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298826] graphics/p5-Image-ExifTool: Update to 13.55 (fixes CVE-2026-7580)"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 298826] graphics/p5-Image-ExifTool: Update to 13.55 (fixes CVE-2026-7580)"
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Thu, 24 Sep 2026 18:55:45 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=298826
Bug ID: 298826
Summary: graphics/p5-Image-ExifTool: Update to 13.55 (fixes
CVE-2026-7580)
Product: Ports & Packages
Version: Latest
Hardware: Any
URL: https://exiftool.sourceforge.net/history.html
OS: Any
Status: New
Keywords: security
Severity: Affects Many People
Priority: ---
Component: Individual Port(s)
Assignee: ports-bugs@FreeBSD.org
Reporter: devnull@apt322.org
CC: ports-secteam@FreeBSD.org
Attachment #275081 maintainer-approval+
Flags:
Flags: merge-quarterly?
Created attachment 275081
--> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=275081&action=edit
Update ExifTool to 13.55 (Fixes CVE-2026-7580)
Please update graphics/p5-Image-ExifTool to 13.55 (current production release).
Security fix:
- CVE-2026-7580: code injection in Process_mrld (lib/Image/ExifTool/GM.pm) when
processing crafted JPEG/QuickTime/MOV/MP4 files with the -ee option. Affects
all versions up to 13.53.
VuXML entry attached as a separate patch.
The range also covers graphics/p5-Image-ExifTool-devel.
Please MFH to 2026Q3 (security fix)
Tested build on a clean Poudriere Jail: 14.4-RELEASE, 14.5-RELEASE and
15.1-RELEASE.
Tested in runtime - pass.
QA tests - happy
--
You are receiving this mail because:
You are the assignee for the bug.