SB2018110829 - Multiple vulnerabilities in GNU Exiv2
Published: November 8, 2018 Updated: October 27, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Integer overflow (CVE-ID: CVE-2018-19107)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD image file.
2) Infinite loop (CVE-ID: CVE-2018-19108)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.
Remediation
Install update from vendor's website.
References
- https://access.redhat.com/errata/RHSA-2019:2101
- https://github.com/Exiv2/exiv2/issues/427
- https://github.com/Exiv2/exiv2/pull/518
- https://lists.debian.org/debian-lts-announce/2019/02/msg00038.html
- https://usn.ubuntu.com/4056-1/
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00009.html
- https://github.com/Exiv2/exiv2/issues/426