{"id":"SUSE-SU-2022:3889-1","summary":"Security update for exiv2","details":"This update for exiv2 fixes the following issues:\n\nUpdated to version 0.27.5 (jsc#PED-1393):\n\n- CVE-2017-1000128: Fixed stack out of bounds read in JPEG2000 parser (bsc#1068871).\n- CVE-2019-13108: Fixed integer overflow PngImage:readMetadata (bsc#1142675).\n- CVE-2020-19716: Fixed buffer overflow vulnerability in the Databuf function in types.cpp (bsc#1188645).\n- CVE-2021-29457: Fixed heap buffer overflow when write metadata into a crafted image file (bsc#1185002).\n- CVE-2021-29470: Fixed out-of-bounds read in Exiv2:Jp2Image:encodeJp2Header (bsc#1185447).\n- CVE-2021-29623: Fixed read of uninitialized memory (bsc#1186053).\n- CVE-2021-31291: Fixed heap-based buffer overflow in jp2image.cpp (bsc#1188733).\n- CVE-2021-32617: Fixed denial of service due to inefficient algorithm (bsc#1186192).\n- CVE-2021-37620: Fixed out-of-bounds read in XmpTextValue:read() (bsc#1189332).\n- CVE-2021-37621: Fixed DoS due to infinite loop in Image:printIFDStructure (bsc#1189333).\n- CVE-2021-37622: Fixed DoS due to infinite loop in JpegBase:printStructure (bsc#1189334)\n- CVE-2021-34334: Fixed DoS due to integer overflow in loop counter(bsc#1189338)\n- CVE-2021-37623: Fixed DoS due to infinite loop in JpegBase:printStructure (bsc#1189335)\n- CVE-2021-29463: Fixed out-of-bounds read in webpimage.cpp (bsc#1185913).\n- CVE-2021-34334: Fixed DoS due to integer overflow in loop counter (bsc#1189338)\n- CVE-2019-13111: Fixed integer overflow in WebPImage:decodeChunks that lead to denial of service (bsc#1142679)\n- CVE-2021-29463: Fixed an out-of-bounds read was found in webpimage.cpp (bsc#1185913)\n\nBugfixes:\n\n- Fixed build using GCC 11 (bsc#1185218).\n\nA new libexiv2-2_27 shared library is shipped, the libexiv2-2_26 is provided only for compatibility now.\n\nPlease recompile your applications using the exiv2 library.\n\n","modified":"2026-03-11T07:21:25.734733Z","published":"2022-11-07T14:26:03Z","related":["CVE-2017-1000128","CVE-2019-13108","CVE-2019-13111","CVE-2020-19716","CVE-2021-29457","CVE-2021-29463","CVE-2021-29470","CVE-2021-29623","CVE-2021-31291","CVE-2021-32617","CVE-2021-34334","CVE-2021-37620","CVE-2021-37621","CVE-2021-37622","CVE-2021-37623"],"upstream":["CVE-2017-1000128","CVE-2019-13108","CVE-2019-13111","CVE-2020-19716","CVE-2021-29457","CVE-2021-29463","CVE-2021-29470","CVE-2021-29623","CVE-2021-31291","CVE-2021-32617","CVE-2021-34334","CVE-2021-37620","CVE-2021-37621","CVE-2021-37622","CVE-2021-37623"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223889-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1068871"},{"type":"REPORT","url":"https://bugzilla.suse.com/1142675"},{"type":"REPORT","url":"https://bugzilla.suse.com/1142679"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185002"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185218"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185447"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185913"},{"type":"REPORT","url":"https://bugzilla.suse.com/1186053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1186192"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188645"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188733"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189332"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189333"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189334"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189335"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189338"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-1000128"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13108"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13111"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-19716"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29457"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29463"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29470"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29623"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-31291"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32617"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-34334"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-37620"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-37621"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-37622"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-37623"}],"affected":[{"package":{"name":"exiv2","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP4","purl":"pkg:rpm/suse/exiv2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.27.5-150400.15.4.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-27":"0.27.5-150400.15.4.1","libexiv2-devel":"0.27.5-150400.15.4.1","libexiv2-xmp-static":"0.27.5-150400.15.4.1","libexiv2-26":"0.26-150400.9.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3889-1.json"}},{"package":{"name":"exiv2-0_26","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP4","purl":"pkg:rpm/suse/exiv2-0_26&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150400.9.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26":"0.26-150400.9.16.1","libexiv2-27":"0.27.5-150400.15.4.1","libexiv2-devel":"0.27.5-150400.15.4.1","libexiv2-xmp-static":"0.27.5-150400.15.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3889-1.json"}},{"package":{"name":"exiv2","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/exiv2&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.27.5-150400.15.4.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-devel":"0.27.5-150400.15.4.1","libexiv2-xmp-static":"0.27.5-150400.15.4.1","exiv2-lang":"0.27.5-150400.15.4.1","exiv2":"0.27.5-150400.15.4.1","libexiv2-26-32bit":"0.26-150400.9.16.1","libexiv2-26":"0.26-150400.9.16.1","libexiv2-27-32bit":"0.27.5-150400.15.4.1","libexiv2-27":"0.27.5-150400.15.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3889-1.json"}},{"package":{"name":"exiv2-0_26","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/exiv2-0_26&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150400.9.16.1"}]}],"ecosystem_specific":{"binaries":[{"libexiv2-26-32bit":"0.26-150400.9.16.1","libexiv2-26":"0.26-150400.9.16.1","libexiv2-27-32bit":"0.27.5-150400.15.4.1","libexiv2-27":"0.27.5-150400.15.4.1","libexiv2-devel":"0.27.5-150400.15.4.1","libexiv2-xmp-static":"0.27.5-150400.15.4.1","exiv2-lang":"0.27.5-150400.15.4.1","exiv2":"0.27.5-150400.15.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3889-1.json"}}],"schema_version":"1.7.5"}