[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2022:3889-1 -- SLES exiv2, libexiv2-26, libexiv2-27, libexiv2-devel, libexiv2-xmp-static

ID: oval:org.secpod.oval:def:89047845Date: (C)2022-11-11   (M)2024-03-19
Class: PATCHFamily: unix




This update for exiv2 fixes the following issues: Updated to version 0.27.5 : - CVE-2017-1000128: Fixed stack out of bounds read in JPEG2000 parser . - CVE-2019-13108: Fixed integer overflow PngImage:readMetadata . - CVE-2020-19716: Fixed buffer overflow vulnerability in the Databuf function in types.cpp . - CVE-2021-29457: Fixed heap buffer overflow when write metadata into a crafted image file . - CVE-2021-29470: Fixed out-of-bounds read in Exiv2:Jp2Image:encodeJp2Header . - CVE-2021-29623: Fixed read of uninitialized memory. - CVE-2021-32617: Fixed denial of service due to inefficient algorithm . - CVE-2021-37620: Fixed out-of-bounds read in XmpTextValue:read . - CVE-2021-37621: Fixed DoS due to infinite loop in Image:printIFDStructure . - CVE-2021-37622: Fixed DoS due to infinite loop in JpegBase:printStructure - CVE-2021-34334: Fixed DoS due to integer overflow in loop counter - CVE-2021-37623: Fixed DoS due to infinite loop in JpegBase:printStructure - CVE-2021-29463: Fixed out-of-bounds read in webpimage.cpp . - CVE-2021-34334: Fixed DoS due to integer overflow in loop counter - CVE-2019-13111: Fixed integer overflow in WebPImage:decodeChunks that lead to denial of service - CVE-2021-29463: Fixed an out-of-bounds read was found in webpimage.cpp Bugfixes: - Fixed build using GCC 11 . A new libexiv2-2_27 shared library is shipped, the libexiv2-2_26 is provided only for compatibility now. Please recompile your applications using the exiv2 library.

Platform:
SUSE Linux Enterprise Desktop 15 SP4
Product:
exiv2
libexiv2-26
libexiv2-27
libexiv2-devel
libexiv2-xmp-static
Reference:
SUSE-SU-2022:3889-1
CVE-2017-1000128
CVE-2019-13108
CVE-2019-13111
CVE-2020-19716
CVE-2021-29457
CVE-2021-29463
CVE-2021-29470
CVE-2021-29623
CVE-2021-32617
CVE-2021-34334
CVE-2021-37620
CVE-2021-37621
CVE-2021-37622
CVE-2021-37623
CVE    14
CVE-2019-13111
CVE-2021-32617
CVE-2019-13108
CVE-2021-37620
...

© SecPod Technologies