Debian 9914 Published by

A libexif security update has been released for Debian GNU/Linux 8 LTS to address an integer overflow issue.



Package : libexif
Version : 0.6.21-2+deb8u1
CVE ID : CVE-2019-9278
Debian Bug : 945948

an out-of-bounds write vulnerability due to an integer overflow was reported in
libexif, a library to parse exif files. This flaw might be leveraged by remote
attackers to cause denial of service, or potentially execute arbitrary code via
crafted image files.

For Debian 8 "Jessie", this problem has been fixed in version
0.6.21-2+deb8u1.

We recommend that you upgrade your libexif packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS