MGASA-2022-0420 - Updated exiv2 packages fix security vulnerability

Publication date: 13 Nov 2022
URL: https://advisories.mageia.org/MGASA-2022-0420.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2022-3756

Affected is the function QuickTimeVideo::userDataDecoder of the file
quicktimevideo.cpp of the component QuickTime Video Handler. The
manipulation leads to integer overflow. It is possible to launch the
attack remotely. (CVE-2022-3756)

References:
- https://bugs.mageia.org/show_bug.cgi?id=31074
- https://github.com/Exiv2/exiv2/issues/2406#issuecomment-1302816492
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3756

SRPMS:
- 8/core/exiv2-0.27.3-1.5.mga8

Mageia 2022-0420: exiv2 security update

Affected is the function QuickTimeVideo::userDataDecoder of the file quicktimevideo.cpp of the component QuickTime Video Handler

Summary

Affected is the function QuickTimeVideo::userDataDecoder of the file quicktimevideo.cpp of the component QuickTime Video Handler. The manipulation leads to integer overflow. It is possible to launch the attack remotely. (CVE-2022-3756)

References

- https://bugs.mageia.org/show_bug.cgi?id=31074

- https://github.com/Exiv2/exiv2/issues/2406#issuecomment-1302816492

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3756

Resolution

MGASA-2022-0420 - Updated exiv2 packages fix security vulnerability

SRPMS

- 8/core/exiv2-0.27.3-1.5.mga8

Severity
Publication date: 13 Nov 2022
URL: https://advisories.mageia.org/MGASA-2022-0420.html
Type: security
CVE: CVE-2022-3756

Related News