|
|
Log in / Subscribe / Register

exiv2: denial of service

Package(s):exiv2 CVE #(s):
Created:March 4, 2016 Updated:March 9, 2016
Description:

From the Red Hat bug report:

Exempi contains code to protect against a denial-service-attack related to XML entity expansion ("billion laughs attack"), but it is not compiled into the Fedora package because BanAllEntityUsage is not defined when the package is compiled.

Alerts:
Mageia MGASA-2016-0101 exempi exiv2 2016-03-07
Fedora FEDORA-2016-ff39572e31 exiv2 2016-03-06
Fedora FEDORA-2016-f802cade15 exiv2 2016-03-03

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds