#22183 closed enhancement (fixed)
exiv2-0.28.7
| Reported by: | Douglas R. Reno | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version
Change History (6)
comment:1 by , 12 months ago
| Priority: | normal → elevated |
|---|
comment:2 by , 12 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 12 months ago
Information on the changes made to Exiv2 can be found at https://github.com/Exiv2/exiv2/issues/3323 (for 0.28.6) and https://github.com/Exiv2/exiv2/issues/3379 (for 0.28.7)
comment:4 by , 12 months ago
The CVEs fixed are:
CVE-2025-54080: https://github.com/Exiv2/exiv2/security/advisories/GHSA-496f-x7cq-cq39 (Out-of-bounds read in Exiv2::EpsImage::writeMetadata() via crafted EPS file)
CVE-2025-55304: https://github.com/Exiv2/exiv2/security/advisories/GHSA-m54q-mm9w-fp6g ( Quadratic performance in ICC profile parsing in JpegBase::readMetadata)
comment:5 by , 12 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 6d90f0f7450604e87ad24f389e4af831785cbdc2
SA-12.4-010 issued.
Note:
See TracTickets
for help on using tickets.

This version contains two low severity security fixes