SUSE-SU-2022:4252-1 -- SLES exiv2, libexiv2-12ID: oval:org.secpod.oval:def:89047978 | Date: (C)2022-12-05 (M)2024-02-19 |
Class: PATCH | Family: unix |
This update for exiv2 fixes the following issues: - CVE-2019-13112: Fixed an uncontrolled memory allocation in PngChunk:parseChunkContent causing denial of service. - CVE-2021-37620: Fixed out-of-bounds read in XmpTextValue:read. - CVE-2021-34334: Fixed a DoS due to integer overflow in loop counter. - CVE-2021-32815: Fixed a deny-of-service due to assertion failure in crwimage_int.cpp . - CVE-2018-20097: Fixed SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroupsu . - CVE-2021-29457: Fixed a heap buffer overflow when write metadata into a crafted image file . - CVE-2021-29473: Fixed out-of-bounds read in Exiv2::Jp2Image:doWriteMetadata .
Platform: |
SUSE Linux Enterprise Server 12 SP3 |
SUSE Linux Enterprise Server 12 SP2 |
SUSE Linux Enterprise Server 12 SP5 |
SUSE Linux Enterprise Server 12 SP4 |