Advisories ยป MGASA-2022-0420

Updated exiv2 packages fix security vulnerability

Publication date: 13 Nov 2022
Modification date: 13 Nov 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-3756

Description

Affected is the function QuickTimeVideo::userDataDecoder of the file
quicktimevideo.cpp of the component QuickTime Video Handler. The
manipulation leads to integer overflow. It is possible to launch the
attack remotely. (CVE-2022-3756)
                

References

SRPMS

8/core