Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 918620 (CVE-2020-18651, CVE-2020-18652) - <media-libs/exempi-2.5.1: multiple vulnerabilities
Summary: <media-libs/exempi-2.5.1: multiple vulnerabilities
Status: CONFIRMED
Alias: CVE-2020-18651, CVE-2020-18652
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa?]
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-26 20:02 UTC by John Helmert III
Modified: 2023-11-26 20:02 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-11-26 20:02:25 UTC
CVE-2020-18651 (https://gitlab.freedesktop.org/libopenraw/exempi/issues/13):

Buffer Overflow vulnerability in function ID3_Support::ID3v2Frame::getFrameValue in exempi 2.5.0 and earlier allows remote attackers to cause a denial of service via opening of crafted audio file with ID3V2 frame.

Patch: https://gitlab.freedesktop.org/libopenraw/exempi/commit/fdd4765a699f9700850098b43b9798b933acb32f

CVE-2020-18652 (https://gitlab.freedesktop.org/libopenraw/exempi/issues/12):

Buffer Overflow vulnerability in WEBP_Support.cpp in exempi 2.5.0 and earlier allows remote attackers to cause a denial of service via opening of crafted webp file.

Patch: https://gitlab.freedesktop.org/libopenraw/exempi/commit/acee2894ceb91616543927c2a6e45050c60f98f7

Fixes in 2.5.1.