Errata overview
Errata ID 447
Date 2018-08-15
Source package exiv2
Fixed in version 0.24-4.1+deb8u1
Description
This update addresses the following issues:
* SIGABRT caused by memory allocation in
  types.cpp:Exiv2::Internal::PngChunk::zlibUncompress() (CVE-2018-10958)
* SIGABRT by triggering an incorrect Safe::add call (CVE-2018-10998)
* heap-based buffer over-read in parseTXTChunk function (CVE-2018-10999)
* heap-based buffer overflow in getData in preview.cpp (CVE-2018-11531)
* integer overflow in getData function in preview.cpp (CVE-2018-12264)
* integer overflow in the LoaderExifJpeg class in preview.cpp
  (CVE-2018-12265)
Additional notes
CVE ID CVE-2018-10958
CVE-2018-10998
CVE-2018-10999
CVE-2018-11531
CVE-2018-12264
CVE-2018-12265
UCS Bug number #47530