diff options
author | Salvatore Bonaccorso <carnil@debian.org> | 2020-02-06 22:22:43 +0100 |
---|---|---|
committer | Salvatore Bonaccorso <carnil@debian.org> | 2020-02-06 22:22:43 +0100 |
commit | 3ad892d074815a517f2a1d8ec799fa696a08d752 (patch) | |
tree | cd6e694839df1794441a79c61e64f8b37203ec22 /english | |
parent | 91e94dc4337feb0f7b705c2d5e18b2c6cd4a636e (diff) |
[DSA 4618-1] libexif security update
Diffstat (limited to 'english')
-rw-r--r-- | english/security/2020/dsa-4618.data | 13 | ||||
-rw-r--r-- | english/security/2020/dsa-4618.wml | 23 |
2 files changed, 36 insertions, 0 deletions
diff --git a/english/security/2020/dsa-4618.data b/english/security/2020/dsa-4618.data new file mode 100644 index 00000000000..757c2f327da --- /dev/null +++ b/english/security/2020/dsa-4618.data @@ -0,0 +1,13 @@ +<define-tag pagetitle>DSA-4618-1 libexif</define-tag> +<define-tag report_date>2020-2-06</define-tag> +<define-tag secrefs>CVE-2019-9278 Bug#945948</define-tag> +<define-tag packages>libexif</define-tag> +<define-tag isvulnerable>yes</define-tag> +<define-tag fixed>yes</define-tag> +<define-tag fixed-section>no</define-tag> + +#use wml::debian::security + + + +</dl> diff --git a/english/security/2020/dsa-4618.wml b/english/security/2020/dsa-4618.wml new file mode 100644 index 00000000000..c56497d475d --- /dev/null +++ b/english/security/2020/dsa-4618.wml @@ -0,0 +1,23 @@ +<define-tag description>security update</define-tag> +<define-tag moreinfo> +<p>An out-of-bounds write vulnerability due to an integer overflow was +reported in libexif, a library to parse EXIF files, which could result +in denial of service, or potentially the execution of arbitrary code if +specially crafted image files are processed.</p> + +<p>For the oldstable distribution (stretch), this problem has been fixed +in version 0.6.21-2+deb9u1.</p> + +<p>For the stable distribution (buster), this problem has been fixed in +version 0.6.21-5.1+deb10u1.</p> + +<p>We recommend that you upgrade your libexif packages.</p> + +<p>For the detailed security status of libexif please refer to its security +tracker page at: +<a href="https://security-tracker.debian.org/tracker/libexif">https://security-tracker.debian.org/tracker/libexif</a></p> +</define-tag> + +# do not modify the following line +#include "$(ENGLISHDIR)/security/2020/dsa-4618.data" +# $Id: $ |