Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE: 2018:1882-1 Moderate: exiv2 Denial of Service Issues

suse
Calendar Grey July 5, 2018
Dist Suse Esm H88
SUSE Security Bulletin: resolves 15 vulnerabilities in exiv2, featuring a moderate risk related to denial of service exploits.
An update that fixes 15 vulnerabilities is now available

Summary

This update for exiv2 to 0.26 fixes the following security issues: - CVE-2017-14864: Prevent invalid memory address dereference in Exiv2::getULong that could have caused a segmentation fault and application crash, which leads to denial of service (bsc#1060995). - CVE-2017-14862: Prevent invalid memory address dereference in Exiv2::DataValue::read that could have caused a segmentation fault and application crash, which leads to denial of service (bsc#1060996). - CVE-2017-14859: Prevent invalid memory address dereference in Exiv2::StringValueBase::read that could have caused a segmentation fault and application crash, which leads to denial of service (bsc#1061000). - CVE-2017-14860: Prevent heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function via a crafted input that could

References

#1048883 #1050257 #1051188 #1054590 #1054592

#1054593 #1060995 #1060996 #1061000 #1061023

Cross- CVE-2017-11337 CVE-2017-11338 CVE-2017-11339

CVE-2017-11340 CVE-2017-11553 CVE-2017-11591

CVE-2017-11592 CVE-2017-11683 CVE-2017-12955

CVE-2017-12956 CVE-2017-12957 CVE-2017-14859

CVE-2017-14860 CVE-2017-14862 CVE-2017-14864

Affected Products:

SUSE Linux Enterprise Module for Desktop Applications 15

https://www.suse.com/security/cve/CVE-2017-11337.html

https://www.suse.com/security/cve/CVE-2017-11338.html

https://www.suse.com/security/cve/CVE-2017-11339.html

https://www.suse.com/security/cve/CVE-2017-11340.html

https://www.suse.com/security/cve/CVE-2017-11553.html

https://www.suse.com/security/cve/CVE-2017-11591.html

Announcement ID: SUSE-SU-2018:1882-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here