[ubuntu/precise-security] libexif_0.6.20-2ubuntu0.1_armhf_translations.tar.gz, libexif_0.6.20-2ubuntu0.1_armel_translations.tar.gz, libexif_0.6.20-2ubuntu0.1_i386_translations.tar.gz, libexif, libexif_0.6.20-2ubuntu0.1_amd64_translations.tar.gz, libexif_0.6.20-2ubuntu0.1_powerpc_translations.tar.gz 0.6.20-2ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Mon Jul 23 18:33:27 UTC 2012


libexif (0.6.20-2ubuntu0.1) precise-security; urgency=low

  * SECURITY UPDATE: denial of service and possible info disclosure via
    corrupted EXIF_TAG_COPYRIGHT tag (LP: #1024213)
    - debian/patches/CVE-2012-2812.patch: fix reading tags that aren't
      NUL-terminated in libexif/exif-entry.c.
    - CVE-2012-2812
  * SECURITY UPDATE: denial of service and possible info disclosure via
    UTF-16 tag (LP: #1024213)
    - debian/patches/CVE-2012-2813.patch: don't read past the end of a
      tag when converting from UTF-16 in libexif/exif-entry.c.
    - CVE-2012-2813
  * SECURITY UPDATE: denial of service and possible code execution via
    crafted tags (LP: #1024213)
    - debian/patches/CVE-2012-2814.patch: fix buffer overflows in
      libexif/exif-entry.c.
    - CVE-2012-2814
  * SECURITY UPDATE: denial of service and possible info disclosure via
    crafted tags (LP: #1024213)
    - debian/patches/CVE-2012-2836.patch: fix buffer overflows in
      libexif/exif-data.c
    - CVE-2012-2836
  * SECURITY UPDATE: denial of service via crafted tags (LP: #1024213)
    - debian/patches/CVE-2012-2837.patch: fix some possible
      division-by-zeros in libexif/olympus/mnote-olympus-entry.c.
    - CVE-2012-2837
  * SECURITY UPDATE: denial of service and possible code execution via
    crafted tags (LP: #1024213)
    - debian/patches/CVE-2012-2840.patch: fix off-by-one in
      libexif/exif-utils.c.
    - CVE-2012-2840
  * SECURITY UPDATE: denial of service and possible code execution via
    incorrect buffer size (LP: #1024213)
    - debian/patches/CVE-2012-2841.patch: validate buffer length in
      libexif/exif-entry.c.
    - CVE-2012-2841

Date: Thu, 19 Jul 2012 13:18:43 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/precise/+source/libexif/0.6.20-2ubuntu0.1
-------------- next part --------------
Format: 1.8
Date: Thu, 19 Jul 2012 13:18:43 -0400
Source: libexif
Binary: libexif-dev libexif12
Architecture: source
Version: 0.6.20-2ubuntu0.1
Distribution: precise-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 libexif-dev - library to parse EXIF files (development files)
 libexif12  - library to parse EXIF files
Launchpad-Bugs-Fixed: 1024213
Changes: 
 libexif (0.6.20-2ubuntu0.1) precise-security; urgency=low
 .
   * SECURITY UPDATE: denial of service and possible info disclosure via
     corrupted EXIF_TAG_COPYRIGHT tag (LP: #1024213)
     - debian/patches/CVE-2012-2812.patch: fix reading tags that aren't
       NUL-terminated in libexif/exif-entry.c.
     - CVE-2012-2812
   * SECURITY UPDATE: denial of service and possible info disclosure via
     UTF-16 tag (LP: #1024213)
     - debian/patches/CVE-2012-2813.patch: don't read past the end of a
       tag when converting from UTF-16 in libexif/exif-entry.c.
     - CVE-2012-2813
   * SECURITY UPDATE: denial of service and possible code execution via
     crafted tags (LP: #1024213)
     - debian/patches/CVE-2012-2814.patch: fix buffer overflows in
       libexif/exif-entry.c.
     - CVE-2012-2814
   * SECURITY UPDATE: denial of service and possible info disclosure via
     crafted tags (LP: #1024213)
     - debian/patches/CVE-2012-2836.patch: fix buffer overflows in
       libexif/exif-data.c
     - CVE-2012-2836
   * SECURITY UPDATE: denial of service via crafted tags (LP: #1024213)
     - debian/patches/CVE-2012-2837.patch: fix some possible
       division-by-zeros in libexif/olympus/mnote-olympus-entry.c.
     - CVE-2012-2837
   * SECURITY UPDATE: denial of service and possible code execution via
     crafted tags (LP: #1024213)
     - debian/patches/CVE-2012-2840.patch: fix off-by-one in
       libexif/exif-utils.c.
     - CVE-2012-2840
   * SECURITY UPDATE: denial of service and possible code execution via
     incorrect buffer size (LP: #1024213)
     - debian/patches/CVE-2012-2841.patch: validate buffer length in
       libexif/exif-entry.c.
     - CVE-2012-2841
Checksums-Sha1: 
 c8fa5b0c27a00d74d780a0547f8d77b4ee471c97 2179 libexif_0.6.20-2ubuntu0.1.dsc
 1346bf9c495e2ee6d204ed253d402dbe60ad962e 14483 libexif_0.6.20-2ubuntu0.1.debian.tar.gz
Checksums-Sha256: 
 e6a8908b5b152eaced7ec6ef5219b891f7a18e8fd3c6d6b17ed1fe1f463ff7ef 2179 libexif_0.6.20-2ubuntu0.1.dsc
 e7adc02811565492f7bc68bf0e3bfe27d59b86e679ef6922046e6919887acdb2 14483 libexif_0.6.20-2ubuntu0.1.debian.tar.gz
Files: 
 13c655c58852a42a006636e2177e28ec 2179 libs optional libexif_0.6.20-2ubuntu0.1.dsc
 c1b9ed7dafd058dd62890fb6eacc1ccb 14483 libs optional libexif_0.6.20-2ubuntu0.1.debian.tar.gz
Original-Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel at lists.alioth.debian.org>


More information about the Precise-changes mailing list