Bugzilla – Bug 1214582
VUL-0: CVE-2020-18831: exiv2: buffer overflow vulnerability in tEXtToDataBuf function in pngimage.cpp
Last modified: 2023-10-16 13:10:07 UTC
CVE-2020-18831 Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-18831 https://www.cve.org/CVERecord?id=CVE-2020-18831 https://github.com/Exiv2/exiv2/issues/828 https://www.exiv2.org/download.html
https://github.com/Exiv2/exiv2/pull/862/commits/20a13f00e2db24c58ee326e4c89a56469718b30e This was fixed in 0.27.2. we have 0.27.5 in SLE15. do we still need to fix SLE11/12 ?
actually SLE12 and older are not affected. SLE15:Update submitted.
This is an autogenerated message for OBS integration: This bug (1214582) was mentioned in https://build.opensuse.org/request/show/1115919 Factory / exiv2