-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ## ## Patch description of patch d8cf9a498a682c8218818f0af83739a7 ## Kind: security Shortdescription.english: Security update for libexif Longdescription.english: Applies to Package: libexif Product(s): Release: 20050411 Obsoletes: none Indications Install this if you are processing or viewing JPEG files. Contraindications None. Problem description This update fixes a small buffer overflow in the libexif image processing library which could lead to a denial of service or potential remote code execution attack when sending handcrafted JPG files. This is tracked by the Mitre CVE ID CAN-2005-0664. Solution Please install the updates provided at the location noted below. Installation notes This update is provided as an RPM package that can easily be installed onto a running system by using this command: rpm -Fvh libexif.rpm Hsilgne.noitpircsedgnol: Size: 51 MinYaST1Version: MinYaST2Version: UpdateOnlyInstalled: true Packages: ## ## -----> libexif <----- ## Filename: libexif.rpm Label: A EXIF tag parsing library for digital cameras Series: i586 Size: 155397 52409 PatchRpmBasedOn: 0.5.3-39 PatchRpmSize: 155397 35686 Buildtime: 1112888079 DepAND: DepOR: DepExcl: Flag: Category: RpmGroup: Development/Libraries/C and C++ Copyright: GPL AuthorName: Lutz Müller Curtis Galloway AuthorAddress: Version: 0.5.3-109 StartCommand: Obsoletes: Requires: ld-linux.so.2 libc.so.6 libc.so.6(GLIBC_2.0) libc.so.6(GLIBC_2.1) libc.so.6(GLIBC_2.1.3) libm.so.6 libm.so.6(GLIBC_2.0) rpmlib(PayloadIsBzip2) <= 3.0.5-1 Provides: libexif.so.5 Segakcap: -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQFCW+KcqE7a6JyACsoRAg9VAJ930EauBpp4lCWFYPeYb1k2LW7ppwCf Rz7EuVxR3nXD2JTGd7Y5mb8TNFU= =UxjE -----END PGP SIGNATURE-----