This update for exiv2 to 0.26 fixes the following security issues: - CVE-2017-14864: Prevent invalid memory address dereference in Exiv2::getULong that could have caused a segmentation fault and application crash, which leads to denial of service (bsc#1060995). - CVE-2017-14862: Prevent invalid memory address dereference in Exiv2::DataValue::read that could have caused a segmentation fault and application crash, which leads to denial of service (bsc#1060996). - CVE-2017-14859: Prevent invalid memory address dereference in Exiv2::StringValueBase::read that could have caused a segmentation fault and application crash, which leads to denial of service (bsc#1061000). - CVE-2017-14860: Prevent heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function via a crafted input that could
#1048883 #1050257 #1051188 #1054590 #1054592
#1054593 #1060995 #1060996 #1061000 #1061023
Cross- CVE-2017-11337 CVE-2017-11338 CVE-2017-11339
CVE-2017-11340 CVE-2017-11553 CVE-2017-11591
CVE-2017-11592 CVE-2017-11683 CVE-2017-12955
CVE-2017-12956 CVE-2017-12957 CVE-2017-14859
CVE-2017-14860 CVE-2017-14862 CVE-2017-14864
Affected Products:
SUSE Linux Enterprise Module for Desktop Applications 15
https://www.suse.com/security/cve/CVE-2017-11337.html
https://www.suse.com/security/cve/CVE-2017-11338.html
https://www.suse.com/security/cve/CVE-2017-11339.html
https://www.suse.com/security/cve/CVE-2017-11340.html
https://www.suse.com/security/cve/CVE-2017-11553.html
https://www.suse.com/security/cve/CVE-2017-11591.html
Get the latest Linux and open source security news straight to your inbox.