rpm package
suse/exiv2&distro=SUSE Linux Enterprise Module for Desktop Applications 15 SP4
pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4
Vulnerabilities (24)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-18898 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Aug 19, 2021 | A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file. | ||
| CVE-2020-18899 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Aug 19, 2021 | An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. | ||
| CVE-2021-37623 | — | < 0.27.5-150400.15.4.1 | 0.27.5-150400.15.4.1 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image | ||
| CVE-2021-37622 | — | < 0.27.5-150400.15.4.1 | 0.27.5-150400.15.4.1 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image | ||
| CVE-2021-37621 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to print the metadata of a crafted image | ||
| CVE-2021-37620 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a craft | ||
| CVE-2021-37619 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte | ||
| CVE-2021-37618 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a craf | ||
| CVE-2021-34334 | — | < 0.27.5-150400.15.4.1 | 0.27.5-150400.15.4.1 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cau | ||
| CVE-2021-31292 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Jul 26, 2021 | An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. | ||
| CVE-2020-19716 | — | < 0.27.5-150400.15.4.1 | 0.27.5-150400.15.4.1 | Jul 13, 2021 | A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS). | ||
| CVE-2021-32617 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | May 17, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to | ||
| CVE-2021-29623 | — | < 0.27.5-150400.15.4.1 | 0.27.5-150400.15.4.1 | May 13, 2021 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleti | ||
| CVE-2021-29463 | — | < 0.27.5-150400.15.4.1 | 0.27.5-150400.15.4.1 | Apr 30, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte | ||
| CVE-2021-29470 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Apr 23, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte | ||
| CVE-2021-29457 | — | < 0.27.5-150400.15.4.1 | 0.27.5-150400.15.4.1 | Apr 19, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted im | ||
| CVE-2019-13111 | — | < 0.27.5-150400.15.4.1 | 0.27.5-150400.15.4.1 | Jun 30, 2019 | A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file. | ||
| CVE-2019-13108 | — | < 0.27.5-150400.15.4.1 | 0.27.5-150400.15.4.1 | Jun 30, 2019 | An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffset. | ||
| CVE-2018-18915 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Nov 3, 2018 | There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack. | ||
| CVE-2018-10772 | Med | 6.5 | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | May 7, 2018 | The tEXtToDataBuf function in pngimage.cpp in Exiv2 through 0.26 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file. |
- CVE-2020-18898Aug 19, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.
- CVE-2020-18899Aug 19, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input.
- CVE-2021-37623Aug 9, 2021affected < 0.27.5-150400.15.4.1fixed 0.27.5-150400.15.4.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image
- CVE-2021-37622Aug 9, 2021affected < 0.27.5-150400.15.4.1fixed 0.27.5-150400.15.4.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image
- CVE-2021-37621Aug 9, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to print the metadata of a crafted image
- CVE-2021-37620Aug 9, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a craft
- CVE-2021-37619Aug 9, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte
- CVE-2021-37618Aug 9, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a craf
- CVE-2021-34334Aug 9, 2021affected < 0.27.5-150400.15.4.1fixed 0.27.5-150400.15.4.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cau
- CVE-2021-31292Jul 26, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
- CVE-2020-19716Jul 13, 2021affected < 0.27.5-150400.15.4.1fixed 0.27.5-150400.15.4.1
A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).
- CVE-2021-32617May 17, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to
- CVE-2021-29623May 13, 2021affected < 0.27.5-150400.15.4.1fixed 0.27.5-150400.15.4.1
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleti
- CVE-2021-29463Apr 30, 2021affected < 0.27.5-150400.15.4.1fixed 0.27.5-150400.15.4.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte
- CVE-2021-29470Apr 23, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte
- CVE-2021-29457Apr 19, 2021affected < 0.27.5-150400.15.4.1fixed 0.27.5-150400.15.4.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted im
- CVE-2019-13111Jun 30, 2019affected < 0.27.5-150400.15.4.1fixed 0.27.5-150400.15.4.1
A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.
- CVE-2019-13108Jun 30, 2019affected < 0.27.5-150400.15.4.1fixed 0.27.5-150400.15.4.1
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffset.
- CVE-2018-18915Nov 3, 2018affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack.
- affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
The tEXtToDataBuf function in pngimage.cpp in Exiv2 through 0.26 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.
Page 1 of 2