exiv2-0.27.3-3.el8

エラータID: AXSA:2021-2366:02

Release date: 
Monday, August 16, 2021 - 12:53
Subject: 
exiv2-0.27.3-3.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Exiv2 is a C++ library to access image metadata, supporting read and write access to the Exif, IPTC and XMP metadata, Exif MakerNote support, extract and delete methods for Exif thumbnails, classes to access Ifd, and support for various image formats.

Security Fix(es):

* exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp (CVE-2021-31291)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2021-31291
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29457. Reason: This candidate is a duplicate of CVE-2021-29457. Notes: All CVE users should reference CVE-2021-29457 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. exiv2-0.27.3-3.el8.src.rpm
    MD5: d2ce867793b2d1ec31e694aaefcca73f
    SHA-256: 6126cb8fee364ed9522a673582c756118825e5b6799cf3658d9e1835de0828db
    Size: 24.98 MB

Asianux Server 8 for x86_64
  1. exiv2-0.27.3-3.el8.x86_64.rpm
    MD5: 640e6b4bde13b196e01258231ec5f8bb
    SHA-256: ee915285237fd5c441d3561e9ac0ab950c814d2de099270554f0219b8c6b3ea2
    Size: 1.00 MB
  2. exiv2-libs-0.27.3-3.el8.x86_64.rpm
    MD5: 86c36a4c828cea8ff743bed6d29eab6f
    SHA-256: 5b85e622c6edc56ae88458ae3b716a7cea7bb4584f5481e8d06a5e03cf432a69
    Size: 855.44 kB
  3. exiv2-libs-0.27.3-3.el8.i686.rpm
    MD5: 209c89318e39226cf7160d59ca8a6f1e
    SHA-256: 424f43ce9088254add0b91c8f2e675aa6113ab21685f9f7d9cd8db44c54ca49c
    Size: 890.27 kB