|
|
Log in / Subscribe / Register

Debian alert DLA-1551-1 (exiv2)

From:  Roberto C. Sánchez <roberto@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 1551-1] exiv2 security update
Date:  Sun, 21 Oct 2018 00:39:07 -0400
Message-ID:  <20181021043907.h4ooviazfn2spxnn@connexer.com>

Package : exiv2 Version : 0.24-4.1+deb8u2 CVE ID : CVE-2018-10958 CVE-2018-10999 CVE-2018-16336 A vulnerability has been discovered in exiv2 (CVE-2018-16336), a C++ library and a command line utility to manage image metadata, resulting in remote denial of service (heap-based buffer over-read/overflow) via a crafted image file. Additionally, this update includes a minor change to the patch for the CVE-2018-10958/CVE-2018-10999 vulnerability first addressed in DLA 1402-1. The initial patch was overly restrictive and has been adjusted to remove the excessive restriction. For Debian 8 "Jessie", these problems have been fixed in version 0.24-4.1+deb8u2. We recommend that you upgrade your exiv2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds