Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 8 Jessie: DLA-2214-1 Critical: libexif DoS And Disclosure

debian lts
Calendar Grey May 18, 2020
Dist Debian Esm H88
Important updates have been applied to libexif to bolster protection for users of Debian 8 Jessie. An upgrade is advised.
Various vulnerabilities have been addressed in libexif, a library to parse EXIF metadata files

Summary

CVE-2016-6328

An integer overflow when parsing the MNOTE entry data of the input
file had been found. This could have caused Denial-of-Service (DoS)
and Information Disclosure (disclosing some critical heap chunk
metadata, even other applications' private data).

CVE-2017-7544

libexif had been vulnerable to out-of-bounds heap read vulnerability
in exif_data_save_data_entry function in libexif/exif-data.c caused
by improper length computation of the allocated data of an ExifMnote
entry which could have caused denial-of-service or possibly information
disclosure.

CVE-2018-20030

An error when processing the EXIF_IFD_INTEROPERABILITY and
EXIF_IFD_EXIF tags within libexif version could have been exploited
to exhaust available CPU resources.

CVE-2020-0093

In exif_data_save_data_entry of exif-data.c, there was a possible out
of bounds read due to a missing bounds check. This could have lead to

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: libexif
Version: 0.6.21-2+deb8u2
CVE ID: CVE-2016-6328 CVE-2017-7544 CVE-2018-20030 CVE-2020-0093
Debian Bug: #960199 #918730 #876466 #873022

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here