#14272: libexif upstream fixes -------------------------+----------------------- Reporter: ken@… | Owner: blfs-book Type: enhancement | Status: new Priority: normal | Milestone: 10.1 Component: BOOK | Version: SVN Severity: normal | Keywords: -------------------------+----------------------- The other security fixes I noticed are for libexif-0.6.22.
Fedora have patches, apparently from upstream, to fix CVE-2020-0181/0198 and CVE-2020-0452. Those were originally reported against android. The first pair are labelled as DOS, but the last one is an oob write on integer overflow, possible remote code execution or disclosure of sensitive information. -- Ticket URL: <http://wiki.linuxfromscratch.org/blfs/ticket/14272> BLFS Trac <http://wiki.linuxfromscratch.org/blfs> Beyond Linux From Scratch -- http://lists.linuxfromscratch.org/listinfo/blfs-book FAQ: http://www.linuxfromscratch.org/blfs/faq.html Unsubscribe: See the above information page