Security Advisories (2)
CVE-2022-23935 (2022-01-25)

lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.

CVE-2021-22204 (2021-04-23)

Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

NAME

Image::ExifTool::ZIP - Read ZIP archive meta information

SYNOPSIS

This module is used by Image::ExifTool

DESCRIPTION

This module contains definitions required by Image::ExifTool to extract meta information from ZIP, GZIP and RAR archives. This includes ZIP-based file types like Office Open XML (DOCX, PPTX and XLSX), Open Document (ODB, ODC, ODF, ODG, ODI, ODP, ODS and ODT), iWork (KEY, PAGES, NUMBERS), Capture One Enhanced Image Package (EIP), Adobe InDesign Markup Language (IDML), and Electronic Publication (EPUB).

AUTHOR

Copyright 2003-2014, Phil Harvey (phil at owl.phy.queensu.ca)

This library is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

REFERENCES

http://www.pkware.com/documents/casestudies/APPNOTE.TXT
http://www.gzip.org/zlib/rfc-gzip.html
http://DataCompression.info/ArchiveFormats/RAR202.txt

SEE ALSO

"ZIP Tags" in Image::ExifTool::TagNames, "OOXML Tags" in Image::ExifTool::TagNames, Image::ExifTool(3pm)