Amazon Linux 2 Security Advisory: ALAS-2025-2728
Advisory Release Date: 2025-01-04 00:04 Pacific
Advisory Updated Date: 2025-01-09 15:39 Pacific
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 version v0.28.1. The vulnerable function, `QuickTimeVideo::NikonTagsDecoder`, was new in v0.28.0, so Exiv2 versions before v0.28 are _not_ affected. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted video file. In most cases this out of bounds read will result in a crash. This bug is fixed in version v0.28.2. Users are advised to upgrade. There are no known workarounds for this vulnerability. (CVE-2024-24826)
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-service was found in Exiv2 version v0.28.1: an unbounded recursion can cause Exiv2 to crash by exhausting the stack. The vulnerable function, `QuickTimeVideo::multipleEntriesDecoder`, was new in v0.28.0, so Exiv2 versions before v0.28 are _not_ affected. The denial-of-service is triggered when Exiv2 is used to read the metadata of a crafted video file. This bug is fixed in version v0.28.2. Users are advised to upgrade. There are no known workarounds for this vulnerability. (CVE-2024-25112)
Affected Packages:
exiv2
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update exiv2 to update your system.
aarch64:
exiv2-0.27.0-4.amzn2.0.5.aarch64
exiv2-devel-0.27.0-4.amzn2.0.5.aarch64
exiv2-libs-0.27.0-4.amzn2.0.5.aarch64
exiv2-debuginfo-0.27.0-4.amzn2.0.5.aarch64
i686:
exiv2-0.27.0-4.amzn2.0.5.i686
exiv2-devel-0.27.0-4.amzn2.0.5.i686
exiv2-libs-0.27.0-4.amzn2.0.5.i686
exiv2-debuginfo-0.27.0-4.amzn2.0.5.i686
noarch:
exiv2-doc-0.27.0-4.amzn2.0.5.noarch
src:
exiv2-0.27.0-4.amzn2.0.5.src
x86_64:
exiv2-0.27.0-4.amzn2.0.5.x86_64
exiv2-devel-0.27.0-4.amzn2.0.5.x86_64
exiv2-libs-0.27.0-4.amzn2.0.5.x86_64
exiv2-debuginfo-0.27.0-4.amzn2.0.5.x86_64