Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

Debian: DLA-1402-1 Critical: Exiv2 Memory Exhaustion and DoS

debian lts
Calendar Grey June 28, 2018
Dist Debian Esm H88
Package : exiv2 Version : 0.24-4.1+deb8u1 CVE ID : CVE-2018-10958 CVE-2018-10998 CVE-2018-10999 CVE-
Several vulnerabilities have been discovered in exiv2, a C++ library and a command line utility to manage image metadata, resulting in denial of service, heap-based buffer over-rea...

Summary

For Debian 8 "Jessie", these problems have been fixed in version
0.24-4.1+deb8u1.

We recommend that you upgrade your exiv2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: exiv2
Version: 0.24-4.1+deb8u1
CVE ID: CVE-2018-10958 CVE-2018-10998 CVE-2018-10999 CVE-2018-11531
Debian Bug: 901706 901707

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here