CVE-2018-20030 (https://nvd.nist.gov/vuln/detail/CVE-2018-20030): An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust available CPU resources.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=bcce9fb0f933198672777469411dd4774bb39ba3 commit bcce9fb0f933198672777469411dd4774bb39ba3 Author: Thomas Deutschmann <whissi@gentoo.org> AuthorDate: 2019-03-04 18:18:27 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2019-03-04 18:18:46 +0000 media-libs/libexif: rev bump to fix CVE-2018-20030 While here, fix C89 compatibility issue, too. Bug: https://bugs.gentoo.org/679418 Package-Manager: Portage-2.3.62, Repoman-2.3.12 Signed-off-by: Thomas Deutschmann <whissi@gentoo.org> .../files/libexif-0.6.21-CVE-2018-20030.patch | 117 +++++++++++++++++++++ ...ibexif-0.6.21-fix-C89-compatibility-issue.patch | 30 ++++++ media-libs/libexif/libexif-0.6.21-r3.ebuild | 52 +++++++++ 3 files changed, 199 insertions(+)
No reason to wait any longer here imo.
amd64 stable
arm stable
sparc stable
ia64 stable
ppc stable
ppc64 stable
hppa stable
x86 stable
GLSA Vote: No Alpha, please continue stabilization.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=fbee6a0b2a8d96991bdc616e243d1fb6ac55e66e commit fbee6a0b2a8d96991bdc616e243d1fb6ac55e66e Author: Tobias Klausmann <klausman@gentoo.org> AuthorDate: 2019-03-28 09:02:59 +0000 Commit: Tobias Klausmann <klausman@gentoo.org> CommitDate: 2019-03-28 09:02:59 +0000 media-libs/libexif-0.6.21-r3: alpha stable Bug: http://bugs.gentoo.org/679418 Signed-off-by: Tobias Klausmann <klausman@gentoo.org> media-libs/libexif/libexif-0.6.21-r3.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
tree is clean.