Debian: New exiv2 packages fix arbitrary code execution
Posted by Benjamin D. Thomas   
Debian Meder Kydyraliev discovered an integer overflow in the thumbnail handling of libexif, the EXIF/IPTC metadata manipulation library, which could result in the execution of arbitrary code.
- ------------------------------------------------------------------------
Debian Security Advisory DSA-1474-1                               Moritz Muehlenhoff
January 23, 2008            
- ------------------------------------------------------------------------

Package        : exiv2
Vulnerability  : integer overflow
Problem type   : local(remote)
Debian-specific: no
CVE Id(s)      : CVE-2007-6353

Meder Kydyraliev discovered an integer overflow in the thumbnail
handling of libexif, the EXIF/IPTC metadata manipulation library, which
could result in the execution of arbitrary code.

For the stable distribution (etch), this problem has been fixed in
version 0.10-1.5.

The old stable distribution (sarge) doesn't contain exiv2 packages.

We recommend that you upgrade your exiv2 packages.

Debian (stable)
- ---------------

Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
