Bug 1142675 - (CVE-2019-13108) VUL-1: CVE-2019-13108: exiv2: integer overflow PngImage:readMetadata leads to denial of service
VUL-1: CVE-2019-13108: exiv2: integer overflow PngImage:readMetadata leads to...
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
Other Other
: P4 - Low : Normal
: ---
Assigned To: Dirk Mueller
Security Team bot
Depends on:
  Show dependency treegraph
Reported: 2019-07-24 15:21 UTC by Wolfgang Frisch
Modified: 2022-11-07 20:21 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Note You need to log in before you can comment on or make changes to this bug.
Comment 3 Dirk Mueller 2022-09-26 19:01:28 UTC
This issue was introduced inhttps://github.com/kevinbackhouse/exiv2/commit/704fc56d52a981ba5945e79266bf3087e8861b3b

which merged in 0.27-rc1. in SLE15 and older we're shipping 0.26 or older, so we're not affected.
Comment 4 Dirk Mueller 2022-09-26 19:02:50 UTC
added bugreference to factory changelog, closing
Comment 5 OBSbugzilla Bot 2022-09-28 16:05:02 UTC
This is an autogenerated message for OBS integration:
This bug (1142675) was mentioned in
https://build.opensuse.org/request/show/1006717 Factory / exiv2
Comment 8 Swamp Workflow Management 2022-11-07 20:21:59 UTC
SUSE-SU-2022:3889-1: An update that solves 15 vulnerabilities, contains one feature and has one errata is now available.

Category: security (important)
Bug References: 1068871,1142675,1142679,1185002,1185218,1185447,1185913,1186053,1186192,1188645,1188733,1189332,1189333,1189334,1189335,1189338
CVE References: CVE-2017-1000128,CVE-2019-13108,CVE-2019-13111,CVE-2020-19716,CVE-2021-29457,CVE-2021-29463,CVE-2021-29470,CVE-2021-29623,CVE-2021-31291,CVE-2021-32617,CVE-2021-34334,CVE-2021-37620,CVE-2021-37621,CVE-2021-37622,CVE-2021-37623
JIRA References: PED-1393
Sources used:
openSUSE Leap 15.4 (src):    exiv2-0.27.5-150400.15.4.1, exiv2-0_26-0.26-150400.9.16.1
SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (src):    exiv2-0.27.5-150400.15.4.1, exiv2-0_26-0.26-150400.9.16.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.