Buffer overflow in Exiv2 - CVE-2019-17402

 

Buffer overflow in Exiv2 - CVE-2019-17402

Published: June 8, 2020 / Updated: June 30, 2020


Vulnerability identifier: #VU28797
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17402
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary in Exiv2::getULong() function in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp. A remote attacker can pass specially crafted data to the application, trigger memory corruption and crash the service.


Affected software

Exiv2
exiv2 (Alpine package)
exiv2-debuginfo
libexiv2-26-32bit-debuginfo
libexiv2-26-32bit
exiv2-lang
libexiv2-doc
libexiv2-devel
libexiv2-26-debuginfo
libexiv2-26
exiv2-debugsource
exiv2
exiv2 (Red Hat package)
exiv2-libs
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Desktop Applications
openSUSE Leap

How to mitigate CVE-2019-17402

Install update from vendor's website.

Exiv2 - update to 0.27.3
exiv2 (Alpine package) - update to 0.26-r1
exiv2-debuginfo - update to 0.26-150000.6.26.1
libexiv2-26-32bit-debuginfo - addressed in versions 0.26-150000.6.26.1, 0.26-150400.9.21.1
libexiv2-26-32bit - addressed in versions 0.26-150000.6.26.1, 0.26-150400.9.21.1
exiv2-lang - update to 0.26-150000.6.26.1
libexiv2-doc - update to 0.26-150000.6.26.1
libexiv2-devel - update to 0.26-150000.6.26.1
libexiv2-26-debuginfo - addressed in versions 0.26-150000.6.26.1, 0.26-150400.9.21.1
libexiv2-26 - addressed in versions 0.26-150000.6.26.1, 0.26-150400.9.21.1
exiv2-debugsource - update to 0.26-150000.6.26.1
exiv2 - update to 0.26-150000.6.26.1
exiv2 (Red Hat package) - addressed in versions 0.27.0-3.el7_8, 0.27.3-2.el8
exiv2 - update to 0.27.3-3
exiv2-libs - update to 0.27.3-3

External References

Related Security Bulletins