Advisories ยป MGASA-2021-0240

Updated exiv2 packages fix security vulnerabilities

Publication date: 08 Jun 2021
Modification date: 08 Jun 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-3482 , CVE-2021-29457 , CVE-2021-29458 , CVE-2021-29463 , CVE-2021-29464 , CVE-2021-29470 , CVE-2021-29473 , CVE-2021-29623 , CVE-2021-32617

Description

The updated packages fix security vulnerabilities:

Heap-based buffer overflow in Jp2Image::readMetadata(). (CVE-2021-3482)

Heap-based buffer overflow in Exiv2::Jp2Image::doWriteMetadata.
(CVE-2021-29457)

Out-of-bounds read in Exiv2::Internal::CrwMap::encode. (CVE-2021-29458)

Exiv2 incorrectly handled certain files.  An attacker could possibly use
this issue to cause a denial of service. (CVE-2021-29463)

Exiv2 incorrectly handled certain files.  An attacker could possibly use
this issue to execute arbitrary code. (CVE-2021-29464)

Out-of-bounds read in Exiv2::Jp2Image::encodeJp2Header. (CVE-2021-29470)

Out-of-bounds read in Exiv2::Jp2Image::doWriteMetadata. (CVE-2021-29473)

Read of uninitialized memory may lead to information leak. (CVE-2021-29623)

DoS due to quadratic complexity in ProcessUTF8Portion. (CVE-2021-32617)
                

References

SRPMS

8/core

7/core