Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:1758

Опубликовано: 18 мая 2021
Источник: rocky
Оценка: Low

Описание

Low: exiv2 security, bug fix, and enhancement update

The exiv2 packages provide a command line utility which can display and manipulate image metadata such as EXIF, LPTC, and JPEG comments.

The following packages have been upgraded to a later upstream version: exiv2 (0.27.3). (BZ#1880984)

Security Fix(es):

  • exiv2: out-of-bounds read in CiffDirectory::readDirectory due to lack of size check (CVE-2019-17402)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.4 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
exiv2x86_642.el8exiv2-0.27.3-2.el8.x86_64.rpm
exiv2-libsi6862.el8exiv2-libs-0.27.3-2.el8.i686.rpm
exiv2-libsx86_642.el8exiv2-libs-0.27.3-2.el8.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.

CVSS3: 6.5
redhat
около 6 лет назад

Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.

CVSS3: 6.5
nvd
около 6 лет назад

Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.

CVSS3: 6.5
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 6.5
debian
около 6 лет назад

Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in ...