Opened 20 months ago
Closed 19 months ago
#21130 closed enhancement (fixed)
exiv2-0.28.5
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | elevated | Milestone: | 12.3 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (5)
comment:1 by , 19 months ago
| Priority: | normal → elevated |
|---|
comment:2 by , 19 months ago
| Milestone: | 12.4 → 12.3 |
|---|
Promote the security fixes for 12.3 following the decision to make another tagging round.
comment:3 by , 19 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:4 by , 19 months ago
Fixed at 2666533887f35afe79f0afcca26b1b4ef92e1104
Security advisory incoming shortly
Note:
See TracTickets
for help on using tickets.

https://github.com/Exiv2/exiv2/security/advisories/GHSA-38h4-fx85-qcx7 states that it's a buffer overflow that allows for arbitrary code execution if a user acts upon a crafted file.