Security Advisories (1)
CVE-2022-23935 (2022-01-25)

lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.

NAME

Image::ExifTool::WritePhotoshop.pl - Write Photoshop IRB meta information

SYNOPSIS

This file is autoloaded by Image::ExifTool::Photoshop.

DESCRIPTION

This file contains routines to write Photoshop metadata.

NOTES

Photoshop IRB blocks may have an associated resource name. By default, the existing name is preserved when rewriting a resource, and an empty name is used when creating a new resource. However, a different resource name may be specified by defining a SetResourceName entry in the tag information hash. With this defined, a new resource name may be appended to the value in the form "VALUE/#NAME#/" (the slashes and hashes are literal). If SetResourceName is anything other than '1', the value is used as a default resource name, and applied if no appended name is provided.

AUTHOR

Copyright 2003-2008, Phil Harvey (phil at owl.phy.queensu.ca)

This library is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

SEE ALSO

Image::ExifTool::Photoshop(3pm), Image::ExifTool(3pm)