The updated packages fix a security vulnerability:
In libexif, there is a possible out of bounds write due to an integer
overflow. This could lead to remote escalation of privilege in the media
content provider with no additional execution privileges needed. User
interaction is needed for exploitation. (CVE-2019-9278)
- https://bugs.mageia.org/show_bug.cgi?id=25674
- https://www.openwall.com/lists/oss-security/2019/11/07/1
- https://www.cve.org/CVERecord?id=CVE-2019-9278
- 7/core/libexif-0.6.21-14.1.mga7
Get the latest Linux and open source security news straight to your inbox.