VYPR

rpm package

suse/exiv2-0_26&distro=SUSE Linux Enterprise Module for Desktop Applications 15 SP4

pkg:rpm/suse/exiv2-0_26&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4

Vulnerabilities (25)

  • CVE-2021-37623Aug 9, 2021
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image

  • CVE-2021-37622Aug 9, 2021
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image

  • CVE-2021-37621Aug 9, 2021
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to print the metadata of a crafted image

  • CVE-2021-37620Aug 9, 2021
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a craft

  • CVE-2021-34334Aug 9, 2021
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cau

  • CVE-2021-32815Aug 9, 2021
    affected < 0.26-150400.9.21.1fixed 0.26-150400.9.21.1

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability

  • CVE-2020-19716Jul 13, 2021
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    A buffer overflow vulnerability in the Databuf function in types.cpp of Exiv2 v0.27.1 leads to a denial of service (DOS).

  • CVE-2021-32617May 17, 2021
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to

  • CVE-2021-29623May 13, 2021
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleti

  • CVE-2021-29463Apr 30, 2021
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte

  • CVE-2021-29473Apr 26, 2021
    affected < 0.26-150400.9.21.1fixed 0.26-150400.9.21.1

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and m

  • CVE-2021-29470Apr 23, 2021
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafte

  • CVE-2021-29457Apr 19, 2021
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted im

  • CVE-2019-17402Oct 9, 2019
    affected < 0.26-150400.9.21.1fixed 0.26-150400.9.21.1

    Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.

  • CVE-2019-13111Jun 30, 2019
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.

  • CVE-2019-13109Jun 30, 2019
    affected < 0.26-150400.9.21.1fixed 0.26-150400.9.21.1

    An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.

  • CVE-2019-13108Jun 30, 2019
    affected < 0.26-150400.9.16.1fixed 0.26-150400.9.16.1

    An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffset.

  • CVE-2019-13110Jun 30, 2019
    affected < 0.26-150400.9.21.1fixed 0.26-150400.9.21.1

    A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.

  • CVE-2018-20099Dec 12, 2018
    affected < 0.26-150400.9.21.1fixed 0.26-150400.9.21.1

    There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

  • CVE-2018-20098Dec 12, 2018
    affected < 0.26-150400.9.21.1fixed 0.26-150400.9.21.1

    There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

Page 1 of 2