Debian Bug report logs -
#298464
libexif10: Vulnerable to buffer overflows
Reported by: Martin Pitt <mpitt@debian.org>
Date: Mon, 7 Mar 2005 17:33:05 UTC
Severity: grave
Tags: patch, security
Fixed in version libexif/0.6.9-5
Done: Frederic Peters <fpeters@debian.org>
Bug is archived. No further changes may be made.
Toggle useless messages
Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Frederic Peters <fpeters@debian.org>:
Bug#298464; Package libexif10.
(full text, mbox, link).
Acknowledgement sent to Martin Pitt <mpitt@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Frederic Peters <fpeters@debian.org>.
(full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
Package: libexif10
Severity: grave
Tags: security patch
Justification: user security hole
Hi!
libexif is vulnerable against some buffer overflows. Please see
https://bugzilla.ubuntulinux.org/show_bug.cgi?id=7152
for details. You can get the Ubuntu patch at
http://patches.ubuntu.com/patches/libexif.security.diff
Thanks,
Martin
-- System Information:
Debian Release: 3.1
APT prefers testing
APT policy: (500, 'testing')
Architecture: i386 (i686)
Kernel: Linux 2.6.11
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Versions of packages libexif10 depends on:
ii libc6 2.3.2.ds1-20 GNU C Library: Shared libraries an
--
Martin Pitt http://www.piware.de
Ubuntu Developer http://www.ubuntulinux.org
Debian GNU/Linux Developer http://www.debian.org
[signature.asc (application/pgp-signature, inline)]
Reply sent to Frederic Peters <fpeters@debian.org>:
You have taken responsibility.
(full text, mbox, link).
Notification sent to Martin Pitt <mpitt@debian.org>:
Bug acknowledged by developer.
(full text, mbox, link).
Message #10 received at 298464-close@bugs.debian.org (full text, mbox, reply):
Source: libexif
Source-Version: 0.6.9-5
We believe that the bug you reported is fixed in the latest version of
libexif, which is due to be installed in the Debian FTP archive:
libexif-dev_0.6.9-5_i386.deb
to pool/main/libe/libexif/libexif-dev_0.6.9-5_i386.deb
libexif10_0.6.9-5_i386.deb
to pool/main/libe/libexif/libexif10_0.6.9-5_i386.deb
libexif_0.6.9-5.diff.gz
to pool/main/libe/libexif/libexif_0.6.9-5.diff.gz
libexif_0.6.9-5.dsc
to pool/main/libe/libexif/libexif_0.6.9-5.dsc
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 298464@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Frederic Peters <fpeters@debian.org> (supplier of updated libexif package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Mon, 7 Mar 2005 18:56:31 +0100
Source: libexif
Binary: libexif10 libexif-dev
Architecture: source i386
Version: 0.6.9-5
Distribution: unstable
Urgency: high
Maintainer: Frederic Peters <fpeters@debian.org>
Changed-By: Frederic Peters <fpeters@debian.org>
Description:
libexif-dev - library to parse EXIF files (development files)
libexif10 - library to parse EXIF files
Closes: 298464
Changes:
libexif (0.6.9-5) unstable; urgency=high
.
* Urgency high since it fixes a security issue.
* Patch provided from Ubuntu by Martin Pitt, written by Sylvain Defresne.
* libexif/exif-data.c: Add buffer size checks in several places before
trying to access it. (closes: #298464)
* Reference: https://bugzilla.ubuntulinux.org/show_bug.cgi?id=7152
* debian/control: reworded description synopsis.
Files:
ea2a9569859ce74f1c07f58cc7bf9dac 579 libs optional libexif_0.6.9-5.dsc
5c75af2ea0bac0cebc858b8ee596d5c7 4322 libs optional libexif_0.6.9-5.diff.gz
593b699131a8b5469b0bd8ea73c4a7ff 66588 libdevel optional libexif-dev_0.6.9-5_i386.deb
be542f3a7366f8c31379447f40a51754 80952 libs optional libexif10_0.6.9-5_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (GNU/Linux)
iD8DBQFCLJaPoR3LsWeD7V4RAryRAJ9Kz1jbhiKz2tc6SvGg8elF1KuM1wCdFyJj
LGwOhNa32GLGWoHtVZUDrLw=
=TTCt
-----END PGP SIGNATURE-----
Bug unarchived.
Request was from Stefano Zacchiroli <zack@debian.org>
to control@bugs.debian.org.
(Sun, 10 Apr 2011 08:46:04 GMT) (full text, mbox, link).
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org.
(Mon, 09 May 2011 07:45:22 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Wed Oct 11 12:07:26 2017;
Machine Name:
buxtehude
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.