File _patchinfo of Package patchinfo.9131
<patchinfo incident="9131">
<issue tracker="bnc" id="1109176">VUL-1: CVE-2018-17230: exiv2: denial of service (heap-based buffer overflow) via a crafted image file in Exiv2::ul2Data in types.cpp</issue>
<issue tracker="bnc" id="1109175">VUL-1: CVE-2018-17229: exiv2: denial of service (heap-based buffer overflow) via a crafted image file in Exiv2::d2Data in types.cpp</issue>
<issue tracker="bnc" id="1068873">VUL-0: CVE-2017-1000126: exiv2 0.26 contains a Stack out of bounds read in webp parser</issue>
<issue tracker="bnc" id="1040973">VUL-1: CVE-2017-9239: exiv2: Segmentation fault in TiffImageEntry::doWriteImage function</issue>
<issue tracker="bnc" id="1097599">VUL-1: CVE-2018-12265: exiv2: integer overflow in the LoaderExifJpeg class in preview.cpp</issue>
<issue tracker="bnc" id="1142684">VUL-0: CVE-2019-13114: exiv2: null-pointer dereference in http.c causing denial of service</issue>
<issue tracker="bnc" id="1109299">VUL-1: CVE-2018-17282: exiv2: The function Exiv2:DataValue:copy in value.cpp has a NULL pointer dereference</issue>
<issue tracker="bnc" id="1117513">VUL-1: CVE-2018-19607: exiv2: Exiv2:isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.</issue>
<issue tracker="bnc" id="1115364">VUL-1: CVE-2018-19108: exiv2: denial of service in Exiv2::PsdImage::readMetadata caused by crafted PSD image file</issue>
<issue tracker="bnc" id="1088424">VUL-1: CVE-2018-9305: exiv2: In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the &quot;== 0x1c&quot; case.</issue>
<issue tracker="bnc" id="1097600">VUL-1: CVE-2018-12264: exiv2: integer overflow in getData function in preview.cpp</issue>
<issue tracker="cve" id="2017-9239"/>
<issue tracker="cve" id="2018-17229"/>
<issue tracker="cve" id="2017-1000126"/>
<issue tracker="cve" id="2018-19607"/>
<issue tracker="cve" id="2018-19108"/>
<issue tracker="cve" id="2018-9305"/>
<issue tracker="cve" id="2018-12264"/>
<issue tracker="cve" id="2018-17282"/>
<issue tracker="cve" id="2018-17230"/>
<issue tracker="cve" id="2018-12265"/>
<issue tracker="cve" id="2019-13114"/>
<category>security</category>
<rating>moderate</rating>
<packager>dirkmueller</packager>
<description>This update for exiv2 fixes the following issues:
exiv2 was updated to latest 0.26 branch, fixing bugs and security issues:
- CVE-2017-1000126: Fixed an out of bounds read in webp parser (bsc#1068873).
- CVE-2017-9239: Fixed a segmentation fault in TiffImageEntry::doWriteImage function (bsc#1040973).
- CVE-2018-12264: Fixed an integer overflow in LoaderTiff::getData() which
might have led to an out-of-bounds read (bsc#1097600).
- CVE-2018-12265: Fixed integer overflows in LoaderExifJpeg which could have
led to memory corruption (bsc#1097599).
- CVE-2018-17229: Fixed a heap based buffer overflow in Exiv2::d2Data via a crafted image (bsc#1109175).
- CVE-2018-17230: Fixed a heap based buffer overflow in Exiv2::d2Data via a crafted image (bsc#1109176).
- CVE-2018-17282: Fixed a null pointer dereference in Exiv2::DataValue::copy (bsc#1109299).
- CVE-2018-19108: Fixed an integer overflow in Exiv2::PsdImage::readMetadata which could have
led to infinite loop (bsc#1115364).
- CVE-2018-19607: Fixed a null pointer dereference in Exiv2::isoSpeed which might have led to denial
of service (bsc#1117513).
- CVE-2018-9305: Fixed an out of bounds read in IptcData::printStructure which might have led to
to information leak or denial of service (bsc#1088424).
- CVE-2019-13114: Fixed a null pointer dereference which might have led to denial of service via
a crafted response of an malicious http server (bsc#1142684).
</description>
<summary>Security update for exiv2</summary>
</patchinfo>