Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2019.2699 [DLA 1855-1] exiv2 security update 22 July 2019 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: exiv2 Publisher: Debian Operating System: Debian GNU/Linux 8 UNIX variants (UNIX, Linux, OSX) Impact/Access: Denial of Service -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2019-13504 Original Bulletin: https://lists.debian.org/debian-lts-announce/2019/07/msg00015.html Comment: This advisory references vulnerabilities in products which run on platforms other than Debian. It is recommended that administrators running exiv2 check for an updated version of the software for their operating system. - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Package : exiv2 Version : 0.24-4.1+deb8u4 CVE ID : CVE-2019-13504 It was discovered that there was an integer overflow vulnerability in exiv2, a tool to manipulate images containing (eg.) EXIF metadata. This could have resulted in a denial of service via a specially- crafted file. For Debian 8 "Jessie", this issue has been fixed in exiv2 version 0.24-4.1+deb8u4. We recommend that you upgrade your exiv2 packages. Regards, - - -- ,''`. : :' : Chris Lamb `. `'` lamby@debian.org / chris-lamb.co.uk `- - -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl0xziUACgkQHpU+J9Qx HliWoA/+I0ruFG93iq5pfTtYyHU5BqGsSLCH3qk1nUv07XLsh+wo606YvTp9fhd8 daI4GtqbJik2b4m1R8PRFlQCd6adnYlRhKUYDfVmO4LekOWEEGhmEzJTBHiMNeKx jixUB7J5tTwWGUUijN5M70eELmFXBK9Cid1yXa5rHPJkMdwlovlZpcX6RXQMIBMQ GRxfqYXvSTcXX6OjuY4yuk65w3pj4AEfzYN5wIq/Pq9MoDH34pFL1gF8e4mAoeQg y5/k1m2oCg5YthyAhJnJ52ZkS1Q+ANKbpGITnOYqTGGEQV40wycG52l3zq66qkL1 R3HhXXXICrvWkvmmBxQWDAlpL/OqcuzALUuQ/4cxKlvrLTPzmTgtDIfdjxwQSYeN qvBJ8Xb4yhUnJ8o6lj7LyWpMlGSsTG5Oy/hzUTOl00r18xoiQZLZLMHEib44VfXu 98iBf/BOC19KLasIu8/2kJDee1IZmM9zi5qGRmBa6I+EHkdmFjgCGZHtSy0xLgzl hGjSYXNc49p8dpqX7124MucfRTXziW4POoK/ryECIRuIaUWoINRs5rKaSwIEZ0xB LNDl18Abgx5fENwSfFYavb8UnD/V4dYUNO5kvewZeHHhS+ZX2JgiTjRRnl1dYw4K dQoyNE7214IKgnx8qwdCkYOSD8Dvq/t3wUAp8aZhro7SaVjYAig= =tr3A - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXTTqbmaOgq3Tt24GAQjo5Q//Xog7jsxfdn5Le9TjKYtxC+ddeg/eV/cz jNBWe4LqQIs0fKJf8ZZ1ggZMKhNq6gUbo+IANIfL06Ao38wlgGozM7bZHOi1kDHj /xjTa1umF4JnYiJrmxfWcAECYpQW6LCWGeZl/HrSrhDIXoZqmiMjOPV/UzNE18sw XzVVluESdBjQosPh3kKW8J1LNc7uokzGs04ls3aN/1FJ+61VTsSflW1asc9bTTOK Y0pPq/sjdZ2SWZLqsTvSLlmkKNsOeKnKrMEr3HOx0yAxAMBLVFgG6ryzcLSa7Svm VA9fw9IglAy6svIcvHn0cgxxi3XCJrTZGI6VjdA6MuRzmOPYEDatoXJBYmW1oSlO cV0IqWlFXY91eJuMDGO4Loz8RyXhF43AQe8A6fyPb+m2HlGhnY1XlXGPApD7end7 N4vfzEAEl+PvZWnJVnnInZhTT9tXSk0N07oquw8EfgD6ACYJCc3QU4RZDNS1c1zJ zHJ/SX8/oCNVAJk/tloqEInbAwCdlbW0CQXy/bv55AUJm1+1qD0SI8tJ0sSyVoRf ylETL3dqwZQ61I86Jmj+CI/xt8WJ1X5q/EsRiPf84/Oq5TZtnAQwh7GPwNSZGM2l ww7MLgJCsCVBU1HQL6HHlFZL2CUrRCdmyou9CAhfxczL5I+eouKGlBg+02hs54yL r5nZ1zfnBPY= =qZbU -----END PGP SIGNATURE-----