SUSE-SU-2018:3882-2
Dashboard / Vulnerabilities / SUSE-SU-2018:3882-2
SUSE-SU-2018:3882-2
Summary: Security update for exiv2
Details: This update for exiv2 fixes the following issues: - CVE-2017-11591: A floating point exception in the Exiv2::ValueType function could lead to a remote denial of service attack via crafted input. (bsc#1050257) - CVE-2017-14864: An invalid memory address dereference was discovered in Exiv2::getULong in types.cpp. The vulnerability caused a segmentation fault and application crash, which lead to denial of service. (bsc#1060995) - CVE-2017-14862: An invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp. The vulnerability caused a segmentation fault and application crash, which lead to denial of service. (bsc#1060996) - CVE-2017-14859: An invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp. The vulnerability caused a segmentation fault and application crash, which lead to denial of service. (bsc#1061000) - CVE-2017-11683: There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp that could lead to a remote denial of service attack via crafted input. (bsc#1051188) - CVE-2017-17669: There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunk_int.cpp. A crafted PNG file would lead to a remote denial of service attack. (bsc#1072928) - CVE-2018-10958: In types.cpp a large size value might have lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call. (bsc#1092952) - CVE-2018-10998: readMetadata in jp2image.cpp allowed remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call. (bsc#1093095) - CVE-2018-11531: Exiv2 had a heap-based buffer overflow in getData in preview.cpp. (bsc#1095070)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183882-2/, https://bugzilla.suse.com/1050257, https://bugzilla.suse.com/1051188, https://bugzilla.suse.com/1060995, https://bugzilla.suse.com/1060996, https://bugzilla.suse.com/1061000, https://bugzilla.suse.com/1072928, https://bugzilla.suse.com/1092952, https://bugzilla.suse.com/1093095, https://bugzilla.suse.com/1095070, https://www.suse.com/security/cve/CVE-2017-11591, https://www.suse.com/security/cve/CVE-2017-11683, https://www.suse.com/security/cve/CVE-2017-14859, https://www.suse.com/security/cve/CVE-2017-14862, https://www.suse.com/security/cve/CVE-2017-14864, https://www.suse.com/security/cve/CVE-2017-17669, https://www.suse.com/security/cve/CVE-2018-10958, https://www.suse.com/security/cve/CVE-2018-10998, https://www.suse.com/security/cve/CVE-2018-11531
Affected packages
Package
Name: exiv2
Purl: pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
