Bug#1060753: exiftags: CVE-2023-50671

2024-01-14 Thread Salvatore Bonaccorso
Hi, On Sun, Jan 14, 2024 at 03:54:59PM +0100, László Böszörményi wrote: > Hi Salvatore, > > On Sat, Jan 13, 2024 at 5:51 PM Salvatore Bonaccorso > wrote: > > If you fix the vulnerability please also make sure to include the > > CVE (Common Vulnerabilities & Exposures) id in your changelog

Bug#1060753: exiftags: CVE-2023-50671

2024-01-14 Thread GCS
Hi Salvatore, On Sat, Jan 13, 2024 at 5:51 PM Salvatore Bonaccorso wrote: > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. I have fixed some issues, but as I see, not the root causes. Then with my fixes I

Bug#1060753: exiftags: CVE-2023-50671

2024-01-13 Thread Salvatore Bonaccorso
Source: exiftags Version: 1.01-7 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi Laszlo, The following vulnerability was published for exiftags. CVE-2023-50671[0]: | In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer | overflow