SUSE-SU-2022:4252-1
Dashboard / Vulnerabilities / SUSE-SU-2022:4252-1
SUSE-SU-2022:4252-1
Summary: Security update for exiv2
Details: This update for exiv2 fixes the following issues: - CVE-2019-13112: Fixed an uncontrolled memory allocation in PngChunk:parseChunkContent causing denial of service. (bsc#1142681) - CVE-2021-37620: Fixed out-of-bounds read in XmpTextValue:read(). (bsc#1189332) - CVE-2021-34334: Fixed a DoS due to integer overflow in loop counter. (bsc#1189338) - CVE-2021-31291: Fixed a heap-based buffer overflow vulnerability in jp2image.cpp may lead to a denial of service via crafted metadata (bsc#1188733). - CVE-2021-32815: Fixed a deny-of-service due to assertion failure in crwimage_int.cpp (bsc#1189337). - CVE-2018-20097: Fixed SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroupsu (bsc#1119562). - CVE-2021-29457: Fixed a heap buffer overflow when write metadata into a crafted image file (bsc#1185002). - CVE-2021-29473: Fixed out-of-bounds read in Exiv2::Jp2Image:doWriteMetadata (bsc#1186231).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20224252-1/, https://bugzilla.suse.com/1119562, https://bugzilla.suse.com/1142681, https://bugzilla.suse.com/1185002, https://bugzilla.suse.com/1186231, https://bugzilla.suse.com/1188733, https://bugzilla.suse.com/1189332, https://bugzilla.suse.com/1189337, https://bugzilla.suse.com/1189338, https://www.suse.com/security/cve/CVE-2018-20097, https://www.suse.com/security/cve/CVE-2019-13112, https://www.suse.com/security/cve/CVE-2021-29457, https://www.suse.com/security/cve/CVE-2021-29473, https://www.suse.com/security/cve/CVE-2021-31291, https://www.suse.com/security/cve/CVE-2021-32815, https://www.suse.com/security/cve/CVE-2021-34334, https://www.suse.com/security/cve/CVE-2021-37620
Affected packages
Package
Name: exiv2
Purl: pkg:rpm/suse/exiv2&distro=SUSE%20OpenStack%20Cloud%209
Affected ranges
Type: ECOSYSTEM
Events:
