Bugzilla – Bug 1172766
VUL-1: CVE-2020-0182: libexif: buffer read overflow in exif_entry_get_value
Last modified: 2020-06-10 12:00:59 UTC
CVE-2020-0182 In exiv2, while parsing EXIF_TAG_FOCAL_LENGTH, it was possible to read 8 bytes past the end of a heap buffer. References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0182 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-0182 http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-0182.html
Upstream commit: https://github.com/libexif/libexif/commit/f9bb9f263fb00f0603ecbefa8957cad24168cbff
actually libexif, not exiv2
covered in the 0.6.22 release we have pushed to SLE12 and SLE15 already.