Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2019-9143: exiv2: infinite recursion at Exiv2:Image:printTiffStructure in the file image.cpp. This can be triggered by a crafted file. It allows an attacker to cause Denial of Servi | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Marcus Meissner <meissner> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | NEW --- | QA Contact: | Security Team bot <security-team> |
Severity: | Major | ||
Priority: | P3 - Medium | CC: | abergmann, rfrohl, smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/225405/ | ||
Whiteboard: | CVSSv3:SUSE:CVE-2019-9143:5.5:(AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) maint:planned:update | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Attachments: | h1 |
Description
Marcus Meissner
2019-02-28 15:46:42 UTC
QA REPRODUCER: exiv2 -b -u -k -p R pr h1 Created attachment 798450 [details]
h1
QA REPRODUCER:
exiv2 -b -u -k -p R pr h1
verified again, we're not affected: bdd765ec4c84:/tmp # rpm -q exiv2 exiv2-0.26-150000.6.38.1.x86_64 bdd765ec4c84:/tmp # exiv2 -b -u -k -p R pr h1 exiv2: Action not available in Release mode: 'R' Usage: exiv2 [ options ] [ action ] file ... Manipulate the Exif metadata of images. bdd765ec4c84:/tmp # exiv2 -b -u -k pr h1 Warning: Directory PanasonicRaw has an unexpected next pointer; ignored. File name : h1 File size : 20268 Bytes MIME type : image/x-panasonic-rw2 Image size : 0 x 0 h1: No Exif data found in the file |