Bugzilla – Bug 1142684
VUL-0: CVE-2019-13114: exiv2: null-pointer dereference in http.c causing denial of service
Last modified: 2022-10-28 17:29:56 UTC
CVE-2019-13114 A vulnerability was discovered in http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character. Reference: https://github.com/Exiv2/exiv2/issues/793 https://github.com/Exiv2/exiv2/pull/815 References: https://bugzilla.redhat.com/show_bug.cgi?id=1728494 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-13114 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-13114.html http://www.cvedetails.com/cve/CVE-2019-13114/ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13114 https://github.com/Exiv2/exiv2/pull/815 https://github.com/Exiv2/exiv2/issues/793 https://usn.ubuntu.com/4056-1/
submitted for SLE15
SUSE-SU-2020:0921-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1040973,1068873,1088424,1097599,1097600,1109175,1109176,1109299,1115364,1117513,1142684 CVE References: CVE-2017-1000126,CVE-2017-9239,CVE-2018-12264,CVE-2018-12265,CVE-2018-17229,CVE-2018-17230,CVE-2018-17282,CVE-2018-19108,CVE-2018-19607,CVE-2018-9305,CVE-2019-13114 Sources used: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): exiv2-0.26-6.8.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP1 (src): exiv2-0.26-6.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2020:0482-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1040973,1068873,1088424,1097599,1097600,1109175,1109176,1109299,1115364,1117513,1142684 CVE References: CVE-2017-1000126,CVE-2017-9239,CVE-2018-12264,CVE-2018-12265,CVE-2018-17229,CVE-2018-17230,CVE-2018-17282,CVE-2018-19108,CVE-2018-19607,CVE-2018-9305,CVE-2019-13114 Sources used: openSUSE Leap 15.1 (src): exiv2-0.26-lp151.7.3.1
Done
This is an autogenerated message for OBS integration: This bug (1142684) was mentioned in https://build.opensuse.org/request/show/1007902 Factory / exiv2