Note:
This project will be discontinued after December 13, 2021. [more]
2018-11-08
In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.
Products | Ubuntu_linux, Debian_linux, Exiv2, Enterprise_linux_desktop, Enterprise_linux_server, Enterprise_linux_workstation |
Type | Loop with Unreachable Exit Condition ('Infinite Loop') (CWE-835) |
First patch | - None (likely due to unavailable code) |
Patches |
• https://github.com/Exiv2/exiv2/pull/518
• https://github.com/Exiv2/exiv2/issues/426 |
Links |
• https://lists.debian.org/debian-lts-announce/2019/02/msg00038.html
• https://usn.ubuntu.com/4056-1/ • http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00009.html • https://lists.debian.org/debian-lts-announce/2023/01/msg00004.html • https://access.redhat.com/errata/RHSA-2019:2101 |