Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora: FEDORA-2019-60553d5a18 Critical: exiv2 Denial Of Service Advisory

New upstream bugfix and security release.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-60553d5a18 2019-08-09 01:02:30.149635 --------------------------------------------------------------------------------Name : exiv2 Product : Fedora 30 Version : 0.27.2 Release : 1.fc30 URL : Summary : Exif and Iptc metadata manipulation library Description : A command line utility to access image metadata, allowing one to: * print the Exif metadata of Jpeg images as summary info, interpreted values, or the plain data for each tag * print the Iptc metadata of Jpeg images * print the Jpeg comment of Jpeg images * set, add and delete Exif and Iptc metadata of Jpeg images * adjust the Exif timestamp (that's how it all started...) * rename Exif image files according to the Exif timestamp * extract, insert and delete Exif metadata (including thumbnails), Iptc metadata and Jpeg comments --------------------------------------------------------------------------------Update Information: New upstream bugfix and security release. --------------------------------------------------------------------------------ChangeLog: * Mon Jul 29 2019 Rex Dieter - 0.27.2-1 - 0.27.2 * Thu Jul 25 2019 Fedora Release Engineering - 0.27.2-0.2.RC2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Tue Jul 16 2019 Rex Dieter - 0.27.2-0.1.RC2 - 0.27.2-RC2 (#1720353) * Fri Apr 26 2019 Rex Dieter - 0.27.1-1 - exiv-0.27.1 (#1696117) --------------------------------------------------------------------------------References: [ 1 ] Bug #1728481 - CVE-2019-13108 exiv2: integer overflow PngImage::readMetadata leads to denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1728481 [ 2 ] Bug #1728484 - CVE-2019-13109 exiv2: denial of service in PngImage::readMetadata https://bugzilla.redhat.com/show_bug.cgi?id=1728484 [ 3 ] Bug #1728486 - CVE-2019-13110 exiv2:integer-overflow and out-of-bounds read in CiffDirectory::readDirectory leads to denail of service https://bugzilla.redhat.com/show_bug.cgi?id=1728486 [ 4 ] Bug #1728488 - CVE-2019-13111 exiv2: integer overflow in WebPImage::decodeChunks leads to denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1728488 [ 5 ] Bug #1728490 - CVE-2019-13112 exiv2: uncontrolled memory allocation in PngChunk::parseChunkContent causing denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1728490 [ 6 ] Bug #1728492 - CVE-2019-13113 exiv2: invalid data location in CRW image file causing denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1728492 [ 7 ] Bug #1728494 - CVE-2019-13114 exiv2: null-pointer dereference in http.c causing denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1728494 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-60553d5a18' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Important security notice regarding exiv2 in Fedora. Several vulnerabilities addressing denial of servicehave been fixed. Ensure your systems are updated promptly.. Fedora Update, exiv2 Security, Denial of Service Fixes, Upstream Bugfix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 08, 2019 Critical Fedora
197

Debian 8: DLA-1691-1 Critical: Exiv2 Denial of Service Issues

Several issues have been found in exiv2, a EXIF/IPTC/XMP metadata manipulation tool. . From: Thorsten Alteholz To: This email address is being protected from spambots. You need JavaScript enabled to view it. Subject: [SECURITY] [DLA 1691-1] exiv2 security update Package : exiv2 Version : 0.24-4.1+deb8u3 CVE ID : CVE-2018-17581 CVE-2018-19107 CVE-2018-19108 CVE-2018-19535 CVE-2018-20097 Several issues have been found in exiv2, a EXIF/IPTC/XMP metadata manipulation tool. CVE-2018-17581 A stack overflow due to a recursive function call causing excessive stack consumption which leads to denial of service. CVE-2018-19107 A heap based buffer over-read caused by an integer overflow could result in a denial of service via a crafted file. CVE-2018-19108 There seems to be an infinite loop inside a function that can be activated by a crafted image. CVE-2018-19535 A heap based buffer over-read caused could result in a denial of service via a crafted file. CVE-2018-20097 A crafted image could result in a denial of service. For Debian 8 "Jessie", these problems have been fixed in version 0.24-4.1+deb8u3. We recommend that you upgrade your exiv2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Important security patch for exiv2 in Debian 8 addressing several vulnerabilities that could result in denial of service.. Exiv2 Update, Debian Security, Metadata Tool Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 26, 2019 Critical Debian LTS
89

Fedora 28: 2018-8b67a5c7e2 Moderate: Exiv2 Security Fix

Exiv2 update with security fixes.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-8b67a5c7e2 2018-08-07 01:13:44.522678 --------------------------------------------------------------------------------Name : exiv2 Product : Fedora 28 Version : 0.26 Release : 12.fc28 URL : Summary : Exif and Iptc metadata manipulation library Description : A command line utility to access image metadata, allowing one to: * print the Exif metadata of Jpeg images as summary info, interpreted values, or the plain data for each tag * print the Iptc metadata of Jpeg images * print the Jpeg comment of Jpeg images * set, add and delete Exif and Iptc metadata of Jpeg images * adjust the Exif timestamp (that's how it all started...) * rename Exif image files according to the Exif timestamp * extract, insert and delete Exif metadata (including thumbnails), Iptc metadata and Jpeg comments --------------------------------------------------------------------------------Update Information: Exiv2 update with security fixes. --------------------------------------------------------------------------------ChangeLog: * Tue Jul 24 2018 Jan Grulich - 0.26-12 - Security fix for CVE-2017-17723, CVE-2017-17725, CVE-2018-10958, CVE-2018-10998, CVE-2018-11531, CVE-2018-12264, CVE-2018-12265, CVE-2018-14046, CVE-2018-5772, CVE-2018-8976, CVE-2018-8977, CVE-2018-9144 * Fri Jul 13 2018 Fedora Release Engineering - 0.26-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Thu May 3 2018 Germano Massullo - 0.26-10 - added patches that fix CVE-2017-17723 CVE-2017-17725 CVE-2017-5772 - moved 0006-1296-Fix-submitted.patch file from sources to package tree * Tue Feb 20 2018 Rex Dieter - 0.26-9 - BR: gcc-c++ --------------------------------------------------------------------------------References: [ 1 ] Bug #1566735 - CVE-2018-9305 exiv2: out of bounds read inIptcData::printStructure in iptc.c https://bugzilla.redhat.com/show_bug.cgi?id=1566735 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-8b67a5c7e2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/HH6QKTBXFX67VYRDSC4O4U34V237UUKC/ . The latest Exiv2 patch for Fedora 28 tackles security vulnerabilities and improves overall system safety. Upgrade now for better defense.. Fedora Exiv2 Update, Security Fixes, Metadata Security, Linux Updates, Threat Mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 07, 2018 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here