/[ports]
ViewVC logotype

Revision 526229


Jump to revision: Previous Next
Author: dbaio
Date: Sat Feb 15 16:28:41 2020 UTC (4 years, 4 months ago)
Changed paths: 3
Log Message:
MFH: r526071

graphics/libexif: Fix security vulnerabilities

 - Fix CVE-2019-9278

  In libexif, there is a possible out of bounds write due to an integer
  overflow. This could lead to remote escalation of privilege in the media
  content provider with no additional execution privileges needed. User
  interaction is needed for exploitation.

 - Fix a buffer read overflow in exif_entry_get_value

 - Fix a buffer overread in exif_mnote_data_olympus_load

PR:		244060
Reported by:	tj@mrsk.me (email)
Approved by:	former maintainer
Security:	00f30cba-4d23-11ea-86ba-641c67a117d8

Approved by:	ports-secteam (blanket, backport of security fixes)


Changed paths

Path Details
Directorybranches/2020Q1/ modified , props changed
Directorybranches/2020Q1/graphics/libexif/Makefile modified , text changed
Directorybranches/2020Q1/graphics/libexif/files/
(Copied from head/graphics/libexif/files, r526071)
added

  ViewVC Help
Powered by ViewVC 1.1.27