rpm package
suse/exiv2&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS
pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOS
Vulnerabilities (25)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-18898 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Aug 19, 2021 | A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file. | ||
| CVE-2020-18899 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Aug 19, 2021 | An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input. | ||
| CVE-2021-37621 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to print the metadata of a crafted image | ||
| CVE-2021-37620 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a craft | ||
| CVE-2021-37619 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte | ||
| CVE-2021-37618 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a craf | ||
| CVE-2021-32815 | — | < 0.26-150000.6.26.1 | 0.26-150000.6.26.1 | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability | ||
| CVE-2021-31292 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Jul 26, 2021 | An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. | ||
| CVE-2021-32617 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | May 17, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to | ||
| CVE-2021-29473 | — | < 0.26-150000.6.26.1 | 0.26-150000.6.26.1 | Apr 26, 2021 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and m | ||
| CVE-2021-29470 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Apr 23, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte | ||
| CVE-2019-17402 | — | < 0.26-150000.6.26.1 | 0.26-150000.6.26.1 | Oct 9, 2019 | Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size. | ||
| CVE-2019-13109 | — | < 0.26-150000.6.26.1 | 0.26-150000.6.26.1 | Jun 30, 2019 | An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction. | ||
| CVE-2019-13110 | — | < 0.26-150000.6.26.1 | 0.26-150000.6.26.1 | Jun 30, 2019 | A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file. | ||
| CVE-2018-20099 | — | < 0.26-150000.6.26.1 | 0.26-150000.6.26.1 | Dec 12, 2018 | There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. | ||
| CVE-2018-20098 | — | < 0.26-150000.6.26.1 | 0.26-150000.6.26.1 | Dec 12, 2018 | There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. | ||
| CVE-2018-20097 | — | < 0.26-150000.6.26.1 | 0.26-150000.6.26.1 | Dec 12, 2018 | There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. | ||
| CVE-2018-18915 | — | < 0.26-150000.6.16.1 | 0.26-150000.6.16.1 | Nov 3, 2018 | There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack. | ||
| CVE-2018-17581 | Med | 6.5 | < 0.26-150000.6.26.1 | 0.26-150000.6.26.1 | Sep 28, 2018 | CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service. | |
| CVE-2018-11531 | Cri | 9.8 | < 0.26-150000.6.26.1 | 0.26-150000.6.26.1 | May 29, 2018 | Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp. |
- CVE-2020-18898Aug 19, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.
- CVE-2020-18899Aug 19, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input.
- CVE-2021-37621Aug 9, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to print the metadata of a crafted image
- CVE-2021-37620Aug 9, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a craft
- CVE-2021-37619Aug 9, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte
- CVE-2021-37618Aug 9, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a craf
- CVE-2021-32815Aug 9, 2021affected < 0.26-150000.6.26.1fixed 0.26-150000.6.26.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability
- CVE-2021-31292Jul 26, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
- CVE-2021-32617May 17, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to
- CVE-2021-29473Apr 26, 2021affected < 0.26-150000.6.26.1fixed 0.26-150000.6.26.1
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and m
- CVE-2021-29470Apr 23, 2021affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte
- CVE-2019-17402Oct 9, 2019affected < 0.26-150000.6.26.1fixed 0.26-150000.6.26.1
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.
- CVE-2019-13109Jun 30, 2019affected < 0.26-150000.6.26.1fixed 0.26-150000.6.26.1
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.
- CVE-2019-13110Jun 30, 2019affected < 0.26-150000.6.26.1fixed 0.26-150000.6.26.1
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.
- CVE-2018-20099Dec 12, 2018affected < 0.26-150000.6.26.1fixed 0.26-150000.6.26.1
There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
- CVE-2018-20098Dec 12, 2018affected < 0.26-150000.6.26.1fixed 0.26-150000.6.26.1
There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
- CVE-2018-20097Dec 12, 2018affected < 0.26-150000.6.26.1fixed 0.26-150000.6.26.1
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
- CVE-2018-18915Nov 3, 2018affected < 0.26-150000.6.16.1fixed 0.26-150000.6.16.1
There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack.
- affected < 0.26-150000.6.26.1fixed 0.26-150000.6.26.1
CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.
- affected < 0.26-150000.6.26.1fixed 0.26-150000.6.26.1
Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.
Page 1 of 2