Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in exiv2
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in exiv2
ID: RHSA-2025:7457
Distribution: Red Hat
Plattformen: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
Datum: Mi, 14. Mai 2025, 06:19
Referenzen: https://access.redhat.com/errata/RHSA-2025:7457
https://bugzilla.redhat.com/show_bug.cgi?id=2346345
https://access.redhat.com/security/cve/CVE-2025-26623
Applikationen: ExiV2

Originalnachricht

An update for exiv2 is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of
Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Exiv2 is a C++ library to access image metadata, supporting read and write
access to the Exif, IPTC and XMP metadata, Exif MakerNote support, extract and delete methods for Exif thumbnails, classes to access Ifd, and support for various image formats.

Security Fix(es):

* exiv2: Use After Free in Exiv2 (CVE-2025-26623)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2025-26623: Use After Free (CWE-416)
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung