QID 198360

Date Published: 2021-05-19

QID 198360: Ubuntu Security Notification for Exiv2 vulnerabilities (USN-4941-1)

Exiv2 incorrectly handled certain images

An attacker could possibly use this issue to execute arbitrary code or cause a crash
(CVE-2021-29457) An attacker could possibly use this issue to cause a denial of service (CVE-2021-29458, CVE-2021-29470) An attacker could possibly use this issue to execute arbitrary code or cause a crash
(CVE-2021-3482)

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to Ubuntu advisory: USN-4941-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198360

    Software Advisories
    Advisory ID Software Component Link
    USN-4941-1 Ubuntu Linux URL Logo usn.ubuntu.com/4941-1