[Git][security-tracker-team/security-tracker][master] exiv2: jessie triage

Sylvain Beucler beuc at debian.org
Wed Jul 3 16:24:53 BST 2019



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
39ab00ec by Sylvain Beucler at 2019-07-03T15:24:18Z
exiv2: jessie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -172,6 +172,7 @@ CVE-2019-13114 (http.c in Exiv2 through 0.27.1 allows a malicious http server to
 	- exiv2 <unfixed> (low)
 	[buster] - exiv2 <ignored> (Minor issue)
 	[stretch] - exiv2 <ignored> (Minor issue)
+	[jessie] - exiv2 <not-affected> (HTTP support yet added in 0.25)
 	NOTE: https://github.com/Exiv2/exiv2/commit/ccde30afa8ca787a3fe17388a15977f107a53b72
 	NOTE: https://github.com/Exiv2/exiv2/issues/793
 CVE-2019-13113 (Exiv2 through 0.27.1 allows an attacker to cause a denial of service ( ...)
@@ -184,6 +185,7 @@ CVE-2019-13112 (A PngChunk::parseChunkContent uncontrolled memory allocation in
 	- exiv2 <unfixed> (low)
 	[buster] - exiv2 <ignored> (Minor issue)
 	[stretch] - exiv2 <ignored> (Minor issue)
+	[jessie] - exiv2 <ignored> (Minor issue, clean exception / local DoS)
 	NOTE: https://github.com/Exiv2/exiv2/commit/1ed1e03c83802547585833fa9d4433af94798778
 	NOTE: https://github.com/Exiv2/exiv2/issues/845
 CVE-2019-13111 (A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 all ...)
@@ -201,12 +203,14 @@ CVE-2019-13109 (An integer overflow in Exiv2 through 0.27.1 allows an attacker t
 	- exiv2 <unfixed> (low)
 	[buster] - exiv2 <ignored> (Minor issue)
 	[stretch] - exiv2 <ignored> (Minor issue)
+	[jessie] - exiv2 <not-affected> (ICC-specific support added in 0.26, PoC doesn't crash)
 	NOTE: https://github.com/Exiv2/exiv2/commit/491c3ebe3b3faa6d8f75fb28146186792c2439da
 	NOTE: https://github.com/Exiv2/exiv2/issues/790
 CVE-2019-13108 (An integer overflow in Exiv2 through 0.27.1 allows an attacker to caus ...)
 	- exiv2 <unfixed> (low)
 	[buster] - exiv2 <ignored> (Minor issue)
 	[stretch] - exiv2 <ignored> (Minor issue)
+	[jessie] - exiv2 <not-affected> (ICC-specific support added in 0.26, PoC doesn't crash)
 	NOTE: https://github.com/Exiv2/exiv2/commit/5d1d6981229b5e44401bf5c503100553fc7d877a
 	NOTE: https://github.com/Exiv2/exiv2/issues/789
 CVE-2019-13107 (Multiple integer overflows exist in MATIO before 1.5.16, related to ma ...)


=====================================
data/dla-needed.txt
=====================================
@@ -18,6 +18,8 @@ cfengine3 (Mike Gabriel)
 --
 dosbox (Markus Koschany)
 --
+exiv2
+--
 faad2
   NOTE: 20190519: I have a few patches pending for open issues. Will be PR-ed soon.
   NOTE: 20190525: see https://github.com/knik0/faad2/pull/36



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/39ab00ec0d0213d9124ddb74ab484b07a04d1faf

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/39ab00ec0d0213d9124ddb74ab484b07a04d1faf
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190703/0b2a0971/attachment.html>


More information about the debian-security-tracker-commits mailing list