shield Security update for exiv2
SUSE-SLE-SDK-12-SP4-2018-2772


This update for exiv2 fixes the following issues: - CVE-2017-11591: A floating point exception in the Exiv2::ValueType function could lead to a remote denial of service attack via crafted input. (bsc#1050257) - CVE-2017-14864: An invalid memory address dereference was discovered in Exiv2::getULong in types.cpp. The vulnerability caused a segmentation fault and application crash, which lead to denial of service. (bsc#1060995) - CVE-2017-14862: An invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp. The vulnerability caused a segmentation fault and application crash, which lead to denial of service. (bsc#1060996) - CVE-2017-14859: An invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp. The vulnerability caused a segmentation fault and application crash, which lead to denial of service. (bsc#1061000) - CVE-2017-11683: There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp that could lead to a remote denial of service attack via crafted input. (bsc#1051188) - CVE-2017-17669: There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunk_int.cpp. A crafted PNG file would lead to a remote denial of service attack. (bsc#1072928) - CVE-2018-10958: In types.cpp a large size value might have lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call. (bsc#1092952) - CVE-2018-10998: readMetadata in jp2image.cpp allowed remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call. (bsc#1093095) - CVE-2018-11531: Exiv2 had a heap-based buffer overflow in getData in preview.cpp. (bsc#1095070)


cloud_download Downloads

SUSE Linux Enterprise Software Development Kit 12.4 aarch64
  • Packages
    exiv2
    Tool to access image Exif metadata
    0.23-12.5.1 lock src
    libexiv2-devel
    Development Headers for Exiv2
    0.23-12.5.1 lock rpm
SUSE Linux Enterprise Software Development Kit 12.4 ppc64le
  • Packages
    exiv2
    Tool to access image Exif metadata
    0.23-12.5.1 lock src
    libexiv2-devel
    Development Headers for Exiv2
    0.23-12.5.1 lock rpm
SUSE Linux Enterprise Software Development Kit 12.4 s390x
  • Packages
    exiv2
    Tool to access image Exif metadata
    0.23-12.5.1 lock src
    libexiv2-devel
    Development Headers for Exiv2
    0.23-12.5.1 lock rpm
SUSE Linux Enterprise Software Development Kit 12.4 x86_64
  • Packages
    exiv2
    Tool to access image Exif metadata
    0.23-12.5.1 lock src
    libexiv2-devel
    Development Headers for Exiv2
    0.23-12.5.1 lock rpm