compat-exiv2-026-0.26-6.el8

エラータID: AXSA:2021-2671:03

Release date: 
Sunday, December 12, 2021 - 09:08
Subject: 
compat-exiv2-026-0.26-6.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

Exiv2 is a C++ library to access image metadata, supporting read and write access to the Exif, IPTC and XMP metadata, Exif MakerNote support, extract and delete methods for Exif thumbnails, classes to access Ifd, and support for various image formats.

Security Fix(es):

* exiv2: Integer overflow in CrwMap:encode0x1810 leading to heap-based buffer overflow and DoS (CVE-2021-31292)
* exiv2: Out-of-bounds read in Exiv2::Jp2Image::printStructure (CVE-2021-37618)
* exiv2: Out-of-bounds read in Exiv2::Jp2Image::encodeJp2Header (CVE-2021-37619)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2021-31292
An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
CVE-2021-37618
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when printing the image ICC profile, which is a less frequently used Exiv2 operation that requires an extra command line option (`-p C`). The bug is fixed in version v0.27.5.
CVE-2021-37619
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as insert. The bug is fixed in version v0.27.5.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. compat-exiv2-026-0.26-6.el8.src.rpm
    MD5: 7021e94d50828f38d5630302679a029a
    SHA-256: 80d571eb2e5c79570c711944017561c5e2f8a6f414f079194c6308343b08d9e2
    Size: 25.67 MB

Asianux Server 8 for x86_64
  1. compat-exiv2-026-0.26-6.el8.x86_64.rpm
    MD5: f36729a642c971f7604c02e3c6bbc3e9
    SHA-256: 0bc075a568cd889b60c6e2168ce91a22372f5d430dcf42d6b664a705445d220e
    Size: 888.00 kB
  2. compat-exiv2-026-0.26-6.el8.i686.rpm
    MD5: 7650f5adc34a45129225410080ab6ed7
    SHA-256: 211035b0a164c173f57fbe964f5b7be836ecc829f85c3a4c4f623f3f4ccc0a04
    Size: 925.79 kB