SUSE-SU-2018:0193-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0193-1
SUSE-SU-2018:0193-1
Summary: Security update for libexif
Details: This update for libexif fixes several issues. These security issues were fixed: - CVE-2016-6328: Fixed integer overflow in parsing MNOTE entry data of the input file (bsc#1055857) - CVE-2017-7544: Fixed out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure (bsc#1059893)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180193-1/, https://bugzilla.suse.com/1055857, https://bugzilla.suse.com/1059893, https://www.suse.com/security/cve/CVE-2016-6328, https://www.suse.com/security/cve/CVE-2017-7544
Affected packages
Package
Name: libexif
Purl: pkg:rpm/suse/libexif&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
