Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2020:0921-1 Moderate: exiv2 Fixes Multiple Issues

suse
Calendar Grey April 3, 2020
Dist Suse Esm H88
SUSE Security Patch addresses 11 vulnerabilities in exiv2, covering severe memory flaws and potential service disruptions.
An update that fixes 11 vulnerabilities is now available

Summary

This update for exiv2 fixes the following issues: exiv2 was updated to latest 0.26 branch, fixing bugs and security issues: - CVE-2017-1000126: Fixed an out of bounds read in webp parser (bsc#1068873). - CVE-2017-9239: Fixed a segmentation fault in TiffImageEntry::doWriteImage function (bsc#1040973). - CVE-2018-12264: Fixed an integer overflow in LoaderTiff::getData() which might have led to an out-of-bounds read (bsc#1097600). - CVE-2018-12265: Fixed integer overflows in LoaderExifJpeg which could have led to memory corruption (bsc#1097599). - CVE-2018-17229: Fixed a heap based buffer overflow in Exiv2::d2Data via a crafted image (bsc#1109175). - CVE-2018-17230: Fixed a heap based buffer overflow in Exiv2::d2Data via a crafted image (bsc#1109176).

References

#1040973 #1068873 #1088424 #1097599 #1097600

#1109175 #1109176 #1109299 #1115364 #1117513

#1142684

Cross- CVE-2017-1000126 CVE-2017-9239 CVE-2018-12264

CVE-2018-12265 CVE-2018-17229 CVE-2018-17230

CVE-2018-17282 CVE-2018-19108 CVE-2018-19607

CVE-2018-9305 CVE-2019-13114

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Desktop Applications 15-SP1

https://www.suse.com/security/cve/CVE-2017-1000126.html

https://www.suse.com/security/cve/CVE-2017-9239.html

https://www.suse.com/security/cve/CVE-2018-12264.html

https://www.suse.com/security/cve/CVE-2018-12265.html

https://www.suse.com/security/cve/CVE-2018-17229.html

Announcement ID: SUSE-SU-2020:0921-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here