- Package:
- src:exiftags
- Source:
- src:exiftags
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2024-01-14 16:48:04 UTC
- Severity:
- normal
- Tags:
Hi Laszlo, The following vulnerability was published for exiftags. CVE-2023-50671[0]: | In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer | overflow (write of size 28) because snprintf can write to an | unexpected address. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2023-50671 https://www.cve.org/CVERecord?id=CVE-2023-50671 [1] https://blog.yulun.ac.cn/posts/2023/fuzzing-exiftags/ Regards, Salvatore
Hi Salvatore, I have fixed some issues, but as I see, not the root causes. Then with my fixes I found that the reproducers may crash exiftags later by other issues. Contacted upstream if he plans to fix these by himself. Waiting for his reply. Regards, Laszlo/GCS
Hi, Sounds like a good plan if there is (still) some activity from upstream. I do not think the isuses are particularly urgent, so take the time it needs to check with upstream availability. Regards, Salvatore