Bugzilla – Bug 1142683
VUL-1: CVE-2019-13113: exiv2: invalid data location in CRW image file causing denial of service
Last modified: 2022-11-18 17:57:59 UTC
CVE-2019-13113 Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file. Reference: https://github.com/Exiv2/exiv2/issues/841 https://github.com/Exiv2/exiv2/pull/842 References: https://bugzilla.redhat.com/show_bug.cgi?id=1728492 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-13113 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-13113.html http://www.cvedetails.com/cve/CVE-2019-13113/ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13113 https://github.com/Exiv2/exiv2/issues/841 https://github.com/Exiv2/exiv2/pull/842 https://usn.ubuntu.com/4056-1/
SUSE-SU-2020:0860-1: An update that fixes 6 vulnerabilities is now available. Category: security (moderate) Bug References: 1040973,1110282,1142678,1142683,1153577,1161901 CVE References: CVE-2017-9239,CVE-2018-17581,CVE-2019-13110,CVE-2019-13113,CVE-2019-17402,CVE-2019-20421 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): exiv2-0.23-12.8.1 SUSE Linux Enterprise Software Development Kit 12-SP4 (src): exiv2-0.23-12.8.1 SUSE Linux Enterprise Server 12-SP5 (src): exiv2-0.23-12.8.1 SUSE Linux Enterprise Server 12-SP4 (src): exiv2-0.23-12.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Already fixed for SLE15. submitted for SLE11 and SLE12