-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2020.3934
                          libexif security update
                              9 November 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           libexif
Publisher:         Debian
Operating System:  Debian GNU/Linux
                   Linux variants
Impact/Access:     Execute Arbitrary Code/Commands -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-0452  

Original Bulletin: 
   https://www.debian.org/lts/security/2020/dla-2439

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Debian. It is recommended that administrators 
         running libexif check for an updated version of the software for 
         their operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- - -----------------------------------------------------------------------
Debian LTS Advisory DLA-2439-1              debian-lts@lists.debian.org
https://www.debian.org/lts/security/                      Utkarsh Gupta
November 07, 2020                           https://wiki.debian.org/LTS
- - -----------------------------------------------------------------------

Package        : libexif
Version        : 0.6.21-2+deb9u5
CVE ID         : CVE-2020-0452

In libexif/exif-entry.c, through libexif 0.6.21-2+deb9u4,
compiler optimization could remove a buffer overflow check,
making a buffer overflow possible with some EXIF tags.

For Debian 9 stretch, this problem has been fixed in version
0.6.21-2+deb9u5.

We recommend that you upgrade your libexif packages.

For the detailed security status of libexif please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libexif

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl+mpqsACgkQgj6WdgbD
S5bQ2RAAhe90x+XPCRjR+aYiB5ZQGKfszbGZW7j84lcd0hjAA/eF+3B/sQCu00wj
bqUjiSG7l5s/s/0tha8LBZhBAkkSEZKTmh+cqrXP7xiVO34USolFZT9P6151pdjO
TG71MR2muonq/8ObfZJGVjFFpVrs7zSCTO19GyYrH/8Zwz0ZHwAeQsv77k1L3mgf
IIe865NZ/idiPCeKpqjtKrUycwRO1AI8dex/6YAKbBRJe+zTsRFf9V/oRnuoC0s/
s3GLbE0ag6kHwwePkd6QniEvoe7apRCHLIF6uvOTVOrRSOZRwl1pFX4c1303dKWE
l5iCFmkNzIOGaW6w07E9fpSXfAVRC1AkZ2n5UJfasrS5ei2oP69usYaqzR+Honrj
xMrVEt6lrxEtnzunqzYgFPjfP8xWwIK7uWdaL9kiPMhkgmMxemQHAFjHPU+H432o
pp+Zq395apSYNWRBPWtapzF/iDCJz+5gre/wENx+1KzMVtXbIAqYOBp2b07FR6T9
v35BoaMmWMxhxQSv6nPcCDa+BiLOgLZzb0vkTByeYNpkjphklDbXCZKax3jWsNt6
j5qF8LYVpSKRLZcc/kOu7djFOnAM+FE7SYNjO6qm1VFWUnZXX6I9/0v0M6FqANqk
W3AQLOQ83aN4cKjeHx7stQfnzgIrPLOpe58ByEdw82R/tPXhPEY=
=vXB8
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBX6jGquNLKJtyKPYoAQjHvxAAmthm3FUm+eg0X42Fwu9P6McYfoYyxt0c
2ZR3eDwkii/i6W/S1RZLzDsc9/kdm4G826eNVZcgC5HoDKBAmwC2EXZrItj6+s9G
DeR42Q/wp8HWxL1TEF+ujA62qZexbDBcOV9XzcrWZWydqiitq7JMlSlhlxwTDDeX
ljIUGa8Z3yF8VjreGTNMzi5hWGVI6QdM5amTFSbbXI3A8ezOlrpCGhbyCwXI/sf5
V4Zrm6mxdUNd+gObW0mi/HTNGuFPXHxp5b4TPzft7WlcPoGGRHaezTt7ZvnOXooi
i1EaM5C3S5BBwbEyaTyqa7Fzs+1fw5TtLz7hZrYIYtGU0Eb6ujdOpqunwtBVXwUv
a1l3bbkoWahU5IoJAVkfoCmu7KC1yIn6GQF6eJFasjKPfvOMX5z9dMShzNEy6dwQ
42AP+VX6rW9YDVlUOxeQQwXWDM3uxKnfDG3TCsFOT9Elmq46/97XSuLpzJ9k+sX1
n10aMBEG44asS3HBESj4z8AANIZMMLADMSMQHvHdWz9TnjH46ah/jS+WsI+Y1d3v
e1OyTwMScyi4zkfEyzBqNJJ6H0DOz6LjE4nVGa9sQxXu+WdqSdDGjakzW2MvOqrq
NzFgOeQHfBfGeQHHuBDx7BYBaOTQ5q1GzZpGQR2CaGHVjL15wENYUJbLlCR14VmN
aEwB1bCASZA=
=EhU5
-----END PGP SIGNATURE-----