Various minor vulnerabilities have been addredd in libexif, a library to
parse EXIF metadata files.
This issue had already been addressed via DLA-2214-1. However, upstream
provided an updated patch, so this has been followed up on.
Several buffer over-reads in EXIF MakerNote handling could have lead
to information disclosure and crashes. This issue is different from
already resolved CVE-2020-0093.
Use of uninitialized memory in EXIF Makernote handling could have
lead to crashes and potential use-after-free conditions.
An unrestricted size in handling Canon EXIF MakerNote data could have
lead to consumption of large amounts of compute time for decoding
For Debian 8 "Jessie", these problems have been fixed in version
We recommend that you upgrade your libexif packages.
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
mike gabriel aka sunweaver (Debian Developer)
fon: +49 (1520) 1976 148
GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31
mail: firstname.lastname@example.org, https://sunweavers.net