MGASA-2018-0051
Dashboard / Vulnerabilities / MGASA-2018-0051
Summary: Updated libexif packages fix security vulnerability
Details: A vulnerability was found in libexif. The vulnerability is caused by an integer overflow. In some cases, the integer overflow can cause Heap Out-of-Bounds Read, i.e. Heap Buffer Overflow vulnerability. In some other cases, the integer overflow can cause use of uninitialized pointer variable, i.e. Use of Uninitialized Variable Vulnerability. The vulnerability happens when parsing MNOTE entry data of the input file. The vulnerability can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metadata, even other applications’ private data) (CVE-2016-6328).
References: https://advisories.mageia.org/MGASA-2018-0051.html, https://bugs.mageia.org/show_bug.cgi?id=22277, https://lists.fedoraproject.org/archives/list/[email protected]/thread/JIGG5FKK6ZHUBJDSP7RIETVHWRZBTPRO/
Affected packages
Package
Name: libexif
Purl: pkg:rpm/mageia/libexif?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
