Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia: 2021-0240 Moderate: Exiv2 Buffer Overflow and DoS Vulnerabilities

mageia
Calendar Grey June 8, 2021
Dist Mageia Esm H88
Recent Mageia updates address numerous vulnerabilities, mitigating risks such as buffer overflows and potential arbitrary code execution.
The updated packages fix security vulnerabilities: Heap-based buffer overflow in Jp2Image::readMetadata()

Summary

The updated packages fix security vulnerabilities:
Heap-based buffer overflow in Jp2Image::readMetadata(). (CVE-2021-3482)
Heap-based buffer overflow in Exiv2::Jp2Image::doWriteMetadata. (CVE-2021-29457)
Out-of-bounds read in Exiv2::Internal::CrwMap::encode. (CVE-2021-29458)
Exiv2 incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2021-29463)
Exiv2 incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2021-29464)
Out-of-bounds read in Exiv2::Jp2Image::encodeJp2Header. (CVE-2021-29470)
Out-of-bounds read in Exiv2::Jp2Image::doWriteMetadata. (CVE-2021-29473)
Read of uninitialized memory may lead to information leak. (CVE-2021-29623)
DoS due to quadratic complexity in ProcessUTF8Portion. (CVE-2021-32617)

References

- https://bugs.mageia.org/show_bug.cgi?id=29008

- https://ubuntu.com/security/notices/USN-4941-1

- https://ubuntu.com/security/notices/USN-4964-1

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/2XQT5F5IINTDYDAFGVGQZ7PMMLG7I5ZZ/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/5I3RRZUGSBIUYZ5TIHLN55PKMAWCSJ5G/

- https://www.cve.org/CVERecord?id=CVE-2021-3482

- https://www.cve.org/CVERecord?id=CVE-2021-29457

- https://www.cve.org/CVERecord?id=CVE-2021-29458

- https://www.cve.org/CVERecord?id=CVE-2021-29463

- https://www.cve.org/CVERecord?id=CVE-2021-29464

- https://www.cve.org/CVERecord?id=CVE-2021-29470

- https://www.cve.org/CVERecord?id=CVE-2021-29473

- https://www.cve.org/CVERecord?id=CVE-2021-29623

- https://www.cve.org/CVERecord?id=CVE-2021-32617

Resolution

SRPMS

- 7/core/exiv2-0.27.1-3.5.mga7

- 8/core/exiv2-0.27.3-1.1.mga8

Publication date: 08 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0240.html
Type: security
CVE: CVE-2021-3482, CVE-2021-29457, CVE-2021-29458, CVE-2021-29463, CVE-2021-29464, CVE-2021-29470, CVE-2021-29473, CVE-2021-29623, CVE-2021-32617

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here