USN-4964-1

Source
https://ubuntu.com/security/notices/USN-4964-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4964-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-4964-1
Related
Published
2021-05-25T14:27:26.892145Z
Modified
2021-05-25T14:27:26.892145Z
Summary
exiv2 vulnerabilities
Details

It was discovered that Exiv2 incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 20.10 and Ubuntu 21.04. (CVE-2021-29463)

It was discovered that Exiv2 incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu 20.10 and Ubuntu 21.04. (CVE-2021-29464)

It was discovered that Exiv2 incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2021-29473, CVE-2021-32617)

It was discovered that Exiv2 incorrectly handled certain files. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 20.04 LTS, Ubuntu 20.10 and Ubuntu 21.04. (CVE-2021-29623)

References

Affected packages

Ubuntu:Pro:16.04:LTS / exiv2

Package

Name
exiv2
Purl
pkg:deb/ubuntu/exiv2?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.25-2.1ubuntu16.04.7+esm2

Affected versions

0.*

0.25-1ubuntu1
0.25-2.1
0.25-2.1ubuntu16.04.1
0.25-2.1ubuntu16.04.2
0.25-2.1ubuntu16.04.3
0.25-2.1ubuntu16.04.4
0.25-2.1ubuntu16.04.5
0.25-2.1ubuntu16.04.6
0.25-2.1ubuntu16.04.7+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "0.25-2.1ubuntu16.04.7+esm2",
            "binary_name": "exiv2"
        },
        {
            "binary_version": "0.25-2.1ubuntu16.04.7+esm2",
            "binary_name": "exiv2-dbgsym"
        },
        {
            "binary_version": "0.25-2.1ubuntu16.04.7+esm2",
            "binary_name": "libexiv2-14"
        },
        {
            "binary_version": "0.25-2.1ubuntu16.04.7+esm2",
            "binary_name": "libexiv2-14-dbgsym"
        },
        {
            "binary_version": "0.25-2.1ubuntu16.04.7+esm2",
            "binary_name": "libexiv2-dbg"
        },
        {
            "binary_version": "0.25-2.1ubuntu16.04.7+esm2",
            "binary_name": "libexiv2-dev"
        },
        {
            "binary_version": "0.25-2.1ubuntu16.04.7+esm2",
            "binary_name": "libexiv2-dev-dbgsym"
        },
        {
            "binary_version": "0.25-2.1ubuntu16.04.7+esm2",
            "binary_name": "libexiv2-doc"
        }
    ]
}

Ubuntu:18.04:LTS / exiv2

Package

Name
exiv2
Purl
pkg:deb/ubuntu/exiv2?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.25-3.1ubuntu0.18.04.9

Affected versions

0.*

0.25-3.1
0.25-3.1ubuntu0.18.04.1
0.25-3.1ubuntu0.18.04.2
0.25-3.1ubuntu0.18.04.3
0.25-3.1ubuntu0.18.04.4
0.25-3.1ubuntu0.18.04.5
0.25-3.1ubuntu0.18.04.7

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "0.25-3.1ubuntu0.18.04.9",
            "binary_name": "exiv2"
        },
        {
            "binary_version": "0.25-3.1ubuntu0.18.04.9",
            "binary_name": "libexiv2-14"
        },
        {
            "binary_version": "0.25-3.1ubuntu0.18.04.9",
            "binary_name": "libexiv2-dbg"
        },
        {
            "binary_version": "0.25-3.1ubuntu0.18.04.9",
            "binary_name": "libexiv2-dev"
        },
        {
            "binary_version": "0.25-3.1ubuntu0.18.04.9",
            "binary_name": "libexiv2-doc"
        }
    ]
}

Ubuntu:20.04:LTS / exiv2

Package

Name
exiv2
Purl
pkg:deb/ubuntu/exiv2?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.27.2-8ubuntu2.4

Affected versions

0.*

0.25-4ubuntu2
0.25-4ubuntu3
0.27.2-8ubuntu2
0.27.2-8ubuntu2.2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "0.27.2-8ubuntu2.4",
            "binary_name": "exiv2"
        },
        {
            "binary_version": "0.27.2-8ubuntu2.4",
            "binary_name": "exiv2-dbgsym"
        },
        {
            "binary_version": "0.27.2-8ubuntu2.4",
            "binary_name": "libexiv2-27"
        },
        {
            "binary_version": "0.27.2-8ubuntu2.4",
            "binary_name": "libexiv2-27-dbgsym"
        },
        {
            "binary_version": "0.27.2-8ubuntu2.4",
            "binary_name": "libexiv2-dev"
        },
        {
            "binary_version": "0.27.2-8ubuntu2.4",
            "binary_name": "libexiv2-doc"
        }
    ]
}