We provide security updates only for the latest release of exif-oxide. Users are encouraged to keep their installations up to date to receive security fixes and improvements.
We take security vulnerabilities seriously. If you discover a security vulnerability within exif-oxide, please follow these steps:
Please do not disclose the vulnerability publicly until we have had a chance to address it.
The preferred method for reporting vulnerabilities is through GitHub's private security vulnerability reporting feature:
- Go to the Security tab of the exif-oxide repository
- Click "Report a vulnerability"
- Fill out the form with as much detail as possible
If you are unable to use GitHub's security reporting feature, you can email security reports to:
- Primary: [maintainer email - to be configured]
- Please use PGP encryption if possible (key ID: [to be configured])
Please provide:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Affected versions
- Potential impact
- Any suggested fixes or mitigations
- Initial Response: Within 48 hours of receiving the report, we will acknowledge receipt
- Initial Assessment: Within 7 days, we will provide an initial assessment of the severity and scope
- Patch Development: We will work on developing a fix as quickly as possible, typically within 30 days for critical issues
- Coordinated Disclosure: We will coordinate with you on the disclosure timeline
- Confirm the vulnerability for the current released version
- Develop a fix and prepare a security patch
- Prepare security advisory documentation
- Release patch for the current released version
- Submit advisory to RustSec Advisory Database
- Update documentation to reference the advisory
- Regularly run
cargo auditto check for known vulnerabilities - Keep dependencies up to date with
cargo update - Consider using
cargo-denyfor more comprehensive dependency management
- Input Validation: Always validate and sanitize EXIF data before using it in security-sensitive contexts
- Memory Safety: While exif-oxide is written in Rust, be aware of potential panics when processing malformed files
- File Sources: Only process EXIF data from trusted sources when possible
- Error Handling: Always handle errors appropriately rather than unwrapping Results
exif-oxide includes several security-focused design decisions:
- Memory Safety: Written in Rust with safe code by default
- Bounds Checking: All offset calculations are bounds-checked
- Input Validation: Validates EXIF structure before processing
- Limited Recursion: Prevents stack overflow from maliciously crafted files
- No Unsafe Code: Minimizes use of unsafe blocks (currently zero unsafe code)
The following are considered security vulnerabilities:
- Memory corruption issues (buffer overflows, use-after-free, etc.)
- Denial of service through resource exhaustion
- Arbitrary code execution
- Information disclosure of sensitive data
- Crashes or panics when processing valid EXIF data
The following are generally NOT considered security vulnerabilities:
- Bugs that only affect incorrect EXIF parsing without security impact
- Performance issues that don't lead to DoS
- Issues in development dependencies
- Missing best practice features (unless they lead to vulnerabilities)
We appreciate security researchers who follow responsible disclosure practices. With your permission, we will acknowledge your contribution in:
- The security advisory
- The project's release notes
- A SECURITY_ACKNOWLEDGMENTS.md file (for significant contributions)