VDB
GCVE-VVD-MAGEIA-2017-391
GCVE-VVD-MAGEIA-2017-391
Advisory Published
Opening an image created on certain pentax cameras with gwenview, which
uses the exiv2 library, causes gwenview to segfault. Exiv2 upstream
created a patch to resolve this problem (bugfix - applies only to mga6).
The following security issues were also fixed:
*Heap overflow in Exiv2::Image::printIFDStructure (CVE-2017-11336)
*Invalid free in the Action::TaskFactory::cleanup function
(CVE-2017-11337)
*Infinite loop in the Exiv2::Image::printIFDStructure function of
image.cpp (CVE-2017-11338)
*Heap-based buffer overflow in the Image::printIFDStructure function of
image.cpp (CVE-2017-11339)
*Segmentation fault in the XmpParser::terminate() function
(CVE-2017-11340)
*Illegal address access in the extend_alias_table function in
localealias.c (CVE-2017-11553)
*Floating point exception in the Exiv2::ValueType function
(CVE-2017-11591)
*Alloc-dealloc-mismatch in Exiv2::FileIo::seek (CVE-2017-11592)
*Reachable assertion in the Internal::TiffReader::visitDirectory
function in tiffvisitor.cpp (CVE-2017-11683)
*Heap-based buffer overflow in basicio.cpp (CVE-2017-12955)
*Illegal address access in Exiv2::FileIo::path[abi:cxx11]() in
basicio.cpp (CVE-2017-12956)
*Heap-based buffer over-read in the Exiv2::Image::io function in
image.cpp (CVE-2017-12957)
*Bad free in Exiv2::Image::~Image (CVE-2017-14857)
*Invalid memory address dereference in Exiv2::DataValue::read
(CVE-2017-14859)
*Heap-buffer-overflow in Exiv2::Jp2Image::readMetadata (CVE-2017-14860)
*Invalid memory address dereference in Exiv2::StringValueBase::read
(CVE-2017-14862)
*Invalid memory address dereference in Exiv2::getULong (CVE-2017-14864)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | exiv2 | 0 (affected), 0.24-5.2.mga5 (unaffected) | — |
| Mageia | exiv2 | 0 (affected), 0.26-2.2.mga6 (unaffected) | — |
Aliases
CVE-2017-11338CVE-2017-11592CVE-2017-11337CVE-2017-14859CVE-2017-14864CVE-2017-11340CVE-2017-12955CVE-2017-12956CVE-2017-11591CVE-2017-11336CVE-2017-11339CVE-2017-11553CVE-2017-12957CVE-2017-11683CVE-2017-14860CVE-2017-14862CVE-2017-14857
Transitive aliases
EUVD-2017-0036EUVD-2017-0042PYSEC-2017-128GHSA-phrg-3g8q-cq66CNVD-2017-27706EUVD-2017-0040PYSEC-2017-120GHSA-43p6-vfwq-xxwgGSD-2017-14859CNVD-2017-16928CNVD-2017-27705PYSEC-2017-123CNVD-2017-28429VVD-GENTOO-2017-628264EUVD-2017-0039GSD-2017-12956CNVD-2017-27704PYSEC-2017-118EUVD-2017-0035EUVD-2017-0051PYSEC-2017-126EUVD-2017-0032GHSA-vrvf-3w78-ffjrBDU:2021-01396GHSA-wcg7-3rc6-c7jgPYSEC-2017-127BDU:2021-01444CNVD-2017-30408EUVD-2017-0044PYSEC-2017-122GHSA-2fr9-r8v5-x2h3GHSA-h9fc-xh5j-xxw8GSD-2017-11592VVD-GENTOO-2017-626352GHSA-h836-f2j9-x39jEUVD-2017-0034EUVD-2017-0046PYSEC-2017-137GSD-2017-14864GHSA-9jx2-c2gh-3r9fCNVD-2017-16930GSD-2017-11553PYSEC-2017-129GHSA-h285-vv62-q7vrEUVD-2017-0047PYSEC-2017-119GHSA-2g3c-rmmx-7hq8GHSA-3436-vqqc-85m3BDU:2021-01397EUVD-2017-0041GHSA-wx7j-vrm5-qqm5CNVD-2017-25749GSD-2017-14857CNVD-2017-16929GSD-2017-11336EUVD-2017-0037CNVD-2017-30414CNVD-2017-25748GHSA-q5fh-m664-3rw6CNVD-2017-16920GSD-2017-11337GSD-2017-11340GSD-2017-12955BDU:2021-01445PYSEC-2017-132GHSA-v685-q6m8-37crCNVD-2017-30412GSD-2017-11591PYSEC-2017-124EUVD-2017-0038PYSEC-2017-130CNVD-2017-30411PYSEC-2017-121CNVD-2017-16927EUVD-2017-0049GSD-2017-11683GSD-2017-11338GHSA-72v4-8c49-whvjGSD-2017-11339PYSEC-2017-133BDU:2021-01446GSD-2017-14862CNVD-2017-26312EUVD-2017-0043GHSA-fh68-7wjw-wh96PYSEC-2017-135PYSEC-2017-125GHSA-hmxp-gvhp-8x2hGSD-2017-12957CNVD-2017-30416GSD-2017-14860EUVD-2017-0033
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.