{"id":"SUSE-SU-2022:3598-1","summary":"Security update for exiv2","details":"This update for exiv2 fixes the following issues:\n\n- CVE-2021-37621: Fixed denial of service due to infinite loop in Image:printIFDStructure (bsc#1189333).\n- CVE-2021-37620: Fixed out-of-bounds read in XmpTextValue:read() (bsc#1189332).\n- CVE-2021-37619: Fixed out-of-bounds read in Exiv2:Jp2Image:encodeJp2Header (bsc#1189331).\n- CVE-2021-37618: Fixed out-of-bounds read in Exiv2:Jp2Image:printStructure (bsc#1189330).\n- CVE-2021-32617: Fixed denial of service inside inefficient algorithm (quadratic complexity) (bsc#1186192).\n- CVE-2021-31292: Fixed integer overflow in CrwMap:encode0x1810 (bsc#1188756).\n- CVE-2021-31291: Fixed heap-based buffer overflow vulnerability in jp2image.cpp may lead to a denial of service (bsc#1188733).\n- CVE-2021-29470: Fixed out-of-bounds read in Exiv2:Jp2Image:encodeJp2Header (bsc#1185447).\n- CVE-2020-18899: Fixed uncontrolled memory allocation (bsc#1189636).\n- CVE-2020-18898: Fixed remote denial of service in printIFDStructure function (bsc#1189780).\n- CVE-2018-8977: Fixed remote denial of service in Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp (bsc#1086798).\n- CVE-2018-8976: Fixed remote denial of service in image.cpp Exiv2::Internal::stringFormat via out-of-bounds read (bsc#1086810).\n- CVE-2018-5772: Fixed segmentation fault caused by uncontrolled recursion inthe Exiv2::Image::printIFDStructure (bsc#1076579).\n- CVE-2018-18915: Fixed an infinite loop in the Exiv2:Image:printIFDStructure function (bsc#1114690).\n- CVE-2018-10772: Fixed segmentation fault when the function Exiv2::tEXtToDataBuf() is finished (bsc#1092096).\n","modified":"2026-03-11T07:21:12.841359Z","published":"2022-10-17T11:19:23Z","related":["CVE-2018-10772","CVE-2018-18915","CVE-2018-5772","CVE-2018-8976","CVE-2018-8977","CVE-2020-18898","CVE-2020-18899","CVE-2021-29470","CVE-2021-31291","CVE-2021-31292","CVE-2021-32617","CVE-2021-37618","CVE-2021-37619","CVE-2021-37620","CVE-2021-37621"],"upstream":["CVE-2018-10772","CVE-2018-18915","CVE-2018-5772","CVE-2018-8976","CVE-2018-8977","CVE-2020-18898","CVE-2020-18899","CVE-2021-29470","CVE-2021-31291","CVE-2021-31292","CVE-2021-32617","CVE-2021-37618","CVE-2021-37619","CVE-2021-37620","CVE-2021-37621"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223598-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1076579"},{"type":"REPORT","url":"https://bugzilla.suse.com/1086798"},{"type":"REPORT","url":"https://bugzilla.suse.com/1086810"},{"type":"REPORT","url":"https://bugzilla.suse.com/1092096"},{"type":"REPORT","url":"https://bugzilla.suse.com/1114690"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185447"},{"type":"REPORT","url":"https://bugzilla.suse.com/1186192"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188733"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188756"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189330"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189331"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189332"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189333"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189636"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189780"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-10772"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-18915"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-5772"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8976"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-8977"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-18898"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-18899"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29470"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-31291"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-31292"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32617"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-37618"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-37619"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-37620"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-37621"}],"affected":[{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP3","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP4","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15-ESPOS","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-devel":"0.26-150000.6.16.1","libexiv2-26":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15-LTSS","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Server 15-LTSS","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Server 15 SP1-BCL","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Server 15 SP1-LTSS","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Server 15 SP2-BCL","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Server 15 SP2-LTSS","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP1","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP2","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Manager Proxy 4.1","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Manager%20Proxy%204.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Manager Retail Branch Server 4.1","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-devel":"0.26-150000.6.16.1","libexiv2-26":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Manager Server 4.1","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Manager%20Server%204.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Enterprise Storage 6","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Enterprise%20Storage%206"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-devel":"0.26-150000.6.16.1","libexiv2-26":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"SUSE:Enterprise Storage 7","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Enterprise%20Storage%207"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/exiv2&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-doc":"0.26-150000.6.16.1","exiv2-lang":"0.26-150000.6.16.1","exiv2":"0.26-150000.6.16.1","libexiv2-26-32bit":"0.26-150000.6.16.1","libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}},{"package":{"name":"exiv2","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/exiv2&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150000.6.16.1"}]}],"ecosystem_specific":{"binaries":[{"exiv2-lang":"0.26-150000.6.16.1","exiv2":"0.26-150000.6.16.1","libexiv2-26-32bit":"0.26-150000.6.16.1","libexiv2-26":"0.26-150000.6.16.1","libexiv2-devel":"0.26-150000.6.16.1","libexiv2-doc":"0.26-150000.6.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3598-1.json"}}],"schema_version":"1.7.5"}