Bug 1061003 - (CVE-2017-14865) VUL-0: CVE-2017-14865: exiv2: It is a heap-buffer-overflow in Exiv2::us2Data (types.cpp:346)
(CVE-2017-14865)
VUL-0: CVE-2017-14865: exiv2: It is a heap-buffer-overflow in Exiv2::us2Data ...
Status: RESOLVED INVALID
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Minor
: ---
Assigned To: Dirk Mueller
Security Team bot
https://smash.suse.de/issue/192623/
CVSSv2:NVD:CVE-2017-14865:4.3:(AV:N/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-09-29 07:42 UTC by Victor Pereira
Modified: 2018-10-18 14:43 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2017-09-29 07:42:08 UTC
rh#1494778

There is a heap-based buffer overflow in the Exiv2::us2Data function of
types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service
attack.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1494778
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14865
http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-14865.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14865
Comment 1 Dirk Mueller 2017-10-17 13:10:09 UTC
submitted for Leap 42.2/42.3
Comment 2 Bernhard Wiedemann 2017-10-17 14:03:10 UTC
This is an autogenerated message for OBS integration:
This bug (1061003) was mentioned in
https://build.opensuse.org/request/show/534433 42.2 / exiv2
https://build.opensuse.org/request/show/534434 42.3 / exiv2
Comment 3 Swamp Workflow Management 2017-10-20 22:09:31 UTC
openSUSE-SU-2017:2818-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1050257,1051188,1060996,1061000,1061003
CVE References: CVE-2017-11591,CVE-2017-11683,CVE-2017-14859,CVE-2017-14862,CVE-2017-14865
Sources used:
openSUSE Leap 42.3 (src):    exiv2-0.25-10.1
openSUSE Leap 42.2 (src):    exiv2-0.25-7.3.1
Comment 7 Dirk Mueller 2018-10-11 12:45:40 UTC
what needs fixing? the fix for this was https://github.com/Exiv2/exiv2/pull/165/commits/1dcf714f4b47fc264bd5bd13365b55e44ce83d3f

and that code path does not exist in sle12 or older.
Comment 8 Johannes Segitz 2018-10-11 13:57:57 UTC
(In reply to Dirk Mueller from comment #7)
yes, initial estimate was incorrect, I adjusted our tracking. Thanks