[<prev] [next>] [day] [month] [year] [list]
Message-id: <E1K9wFY-0004Ur-AQ@titan.mandriva.com>
Date: Sat, 21 Jun 2008 00:07:00 -0600
From: security@...driva.com
To: full-disclosure@...ts.grok.org.uk
Subject: [ MDVSA-2008:119 ] - Updated exiv2 packages fix
vulnerability
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDVSA-2008:119
http://www.mandriva.com/security/
_______________________________________________________________________
Package : exiv2
Date : June 19, 2008
Affected: 2007.1, 2008.0, 2008.1
_______________________________________________________________________
Problem Description:
A flaw was found in exiv2 that would cause exiv2, or applictions linked
to libexiv2, to crash on image files with certain metadata in the image
(CVE-2008-2696).
The updated packages have been patched to prevent this issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2696
_______________________________________________________________________
Updated Packages:
Mandriva Linux 2007.1:
137ec114723baf0d68d42905db8b8e33 2007.1/i586/exiv2-0.13-1.2mdv2007.1.i586.rpm
ba496c25fae6bc9c2f11211d8a89f9c1 2007.1/i586/libexiv2-0.13-1.2mdv2007.1.i586.rpm
c70a9fa23b6d44a94283ac82450c868b 2007.1/i586/libexiv2-devel-0.13-1.2mdv2007.1.i586.rpm
a79c44c1d7fa86dcfeca9764e8e15ee0 2007.1/SRPMS/exiv2-0.13-1.2mdv2007.1.src.rpm
Mandriva Linux 2007.1/X86_64:
359e786ec723e0e2e7d486e84e8881c6 2007.1/x86_64/exiv2-0.13-1.2mdv2007.1.x86_64.rpm
479ddc4f5fca0cae1fe82b7c1d36b25f 2007.1/x86_64/lib64exiv2-0.13-1.2mdv2007.1.x86_64.rpm
55d15a99a63b56e08aee64f7764c1159 2007.1/x86_64/lib64exiv2-devel-0.13-1.2mdv2007.1.x86_64.rpm
a79c44c1d7fa86dcfeca9764e8e15ee0 2007.1/SRPMS/exiv2-0.13-1.2mdv2007.1.src.rpm
Mandriva Linux 2008.0:
50b49d19718687c430b2991d41432387 2008.0/i586/exiv2-0.15-2.2mdv2008.0.i586.rpm
31fc362f85f0d642ec7813d422a6b260 2008.0/i586/libexiv2-0.15-2.2mdv2008.0.i586.rpm
9da5055f6a7b5ffd3e23be557bba0e08 2008.0/i586/libexiv2-devel-0.15-2.2mdv2008.0.i586.rpm
c8cf851fb5e77386e255908a2b7f9ba5 2008.0/SRPMS/exiv2-0.15-2.2mdv2008.0.src.rpm
Mandriva Linux 2008.0/X86_64:
d58c54957f4a135b1264c0961660ed48 2008.0/x86_64/exiv2-0.15-2.2mdv2008.0.x86_64.rpm
042331921b92b72512d428659dda09f0 2008.0/x86_64/lib64exiv2-0.15-2.2mdv2008.0.x86_64.rpm
da07bde17caea7c8c3bcd3e46f1bc14b 2008.0/x86_64/lib64exiv2-devel-0.15-2.2mdv2008.0.x86_64.rpm
c8cf851fb5e77386e255908a2b7f9ba5 2008.0/SRPMS/exiv2-0.15-2.2mdv2008.0.src.rpm
Mandriva Linux 2008.1:
69b4af073a960edc70b54d117d280760 2008.1/i586/exiv2-0.16-3.1mdv2008.1.i586.rpm
223e0e2bbbd9affa6d28b1c15109eb91 2008.1/i586/libexiv2_2-0.16-3.1mdv2008.1.i586.rpm
735c29dc07f50d7a7e56ad4b0bb862ff 2008.1/i586/libexiv2_2-devel-0.16-3.1mdv2008.1.i586.rpm
e571687d2755d0329d6b27f7d9701042 2008.1/SRPMS/exiv2-0.16-3.1mdv2008.1.src.rpm
Mandriva Linux 2008.1/X86_64:
1cf7ec6ed39fd9b1622ad85f3b294b3b 2008.1/x86_64/exiv2-0.16-3.1mdv2008.1.x86_64.rpm
6a1e8eae411f48a28463f922c1d1ba09 2008.1/x86_64/lib64exiv2_2-0.16-3.1mdv2008.1.x86_64.rpm
0f18947fdf8ed8a3b265cab81d4f305f 2008.1/x86_64/lib64exiv2_2-devel-0.16-3.1mdv2008.1.x86_64.rpm
e571687d2755d0329d6b27f7d9701042 2008.1/SRPMS/exiv2-0.16-3.1mdv2008.1.src.rpm
_______________________________________________________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/security/advisories
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iD8DBQFIXG/qmqjQ0CJFipgRApeGAJwIgBJ5rAqtnS1nrojl5L8ZkRSM4wCeKEjl
NgFejtymEXzoMsOqC2tkiwg=
=s2Fh
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists