Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
SUSE:SLE-15-SP1:GA
patchinfo.9131
_patchinfo
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File _patchinfo of Package patchinfo.9131
<patchinfo incident="9131"> <issue tracker="bnc" id="1109176">VUL-1: CVE-2018-17230: exiv2: denial of service (heap-based buffer overflow) via a crafted image file in Exiv2::ul2Data in types.cpp</issue> <issue tracker="bnc" id="1109175">VUL-1: CVE-2018-17229: exiv2: denial of service (heap-based buffer overflow) via a crafted image file in Exiv2::d2Data in types.cpp</issue> <issue tracker="bnc" id="1068873">VUL-0: CVE-2017-1000126: exiv2 0.26 contains a Stack out of bounds read in webp parser</issue> <issue tracker="bnc" id="1040973">VUL-1: CVE-2017-9239: exiv2: Segmentation fault in TiffImageEntry::doWriteImage function</issue> <issue tracker="bnc" id="1097599">VUL-1: CVE-2018-12265: exiv2: integer overflow in the LoaderExifJpeg class in preview.cpp</issue> <issue tracker="bnc" id="1142684">VUL-0: CVE-2019-13114: exiv2: null-pointer dereference in http.c causing denial of service</issue> <issue tracker="bnc" id="1109299">VUL-1: CVE-2018-17282: exiv2: The function Exiv2:DataValue:copy in value.cpp has a NULL pointer dereference</issue> <issue tracker="bnc" id="1117513">VUL-1: CVE-2018-19607: exiv2: Exiv2:isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.</issue> <issue tracker="bnc" id="1115364">VUL-1: CVE-2018-19108: exiv2: denial of service in Exiv2::PsdImage::readMetadata caused by crafted PSD image file</issue> <issue tracker="bnc" id="1088424">VUL-1: CVE-2018-9305: exiv2: In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the &quot;== 0x1c&quot; case.</issue> <issue tracker="bnc" id="1097600">VUL-1: CVE-2018-12264: exiv2: integer overflow in getData function in preview.cpp</issue> <issue tracker="cve" id="2017-9239"/> <issue tracker="cve" id="2018-17229"/> <issue tracker="cve" id="2017-1000126"/> <issue tracker="cve" id="2018-19607"/> <issue tracker="cve" id="2018-19108"/> <issue tracker="cve" id="2018-9305"/> <issue tracker="cve" id="2018-12264"/> <issue tracker="cve" id="2018-17282"/> <issue tracker="cve" id="2018-17230"/> <issue tracker="cve" id="2018-12265"/> <issue tracker="cve" id="2019-13114"/> <category>security</category> <rating>moderate</rating> <packager>dirkmueller</packager> <description>This update for exiv2 fixes the following issues: exiv2 was updated to latest 0.26 branch, fixing bugs and security issues: - CVE-2017-1000126: Fixed an out of bounds read in webp parser (bsc#1068873). - CVE-2017-9239: Fixed a segmentation fault in TiffImageEntry::doWriteImage function (bsc#1040973). - CVE-2018-12264: Fixed an integer overflow in LoaderTiff::getData() which might have led to an out-of-bounds read (bsc#1097600). - CVE-2018-12265: Fixed integer overflows in LoaderExifJpeg which could have led to memory corruption (bsc#1097599). - CVE-2018-17229: Fixed a heap based buffer overflow in Exiv2::d2Data via a crafted image (bsc#1109175). - CVE-2018-17230: Fixed a heap based buffer overflow in Exiv2::d2Data via a crafted image (bsc#1109176). - CVE-2018-17282: Fixed a null pointer dereference in Exiv2::DataValue::copy (bsc#1109299). - CVE-2018-19108: Fixed an integer overflow in Exiv2::PsdImage::readMetadata which could have led to infinite loop (bsc#1115364). - CVE-2018-19607: Fixed a null pointer dereference in Exiv2::isoSpeed which might have led to denial of service (bsc#1117513). - CVE-2018-9305: Fixed an out of bounds read in IptcData::printStructure which might have led to to information leak or denial of service (bsc#1088424). - CVE-2019-13114: Fixed a null pointer dereference which might have led to denial of service via a crafted response of an malicious http server (bsc#1142684). </description> <summary>Security update for exiv2</summary> </patchinfo>
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor