Update to exiv2 version 0.27

Bug #1715931 reported by Rik Mills
26
This bug affects 3 people
Affects Status Importance Assigned to Milestone
exiv2 (Debian)
Fix Released
Unknown
exiv2 (Ubuntu)
Fix Released
Wishlist
Unassigned
Focal
Fix Released
Wishlist
Unassigned

Bug Description

0.26 was released in April

http://www.exiv2.org/whatsnew.html

"This release contains a large collection of new features, new lenses and bugfixes across all areas of Exiv2. "

Presumably debian stretch freeze interfered with a prompter update

Currently in debian exp here:

https://packages.debian.org/experimental/exiv2

I was hoping to to get a new feature release of the very popular Digikam (5.7.0) into artful under a FFE, but that has bumped the minimum exiv2 build depend from 0.25 -> 0.26.

If due to rdeps etc an update in artful turns out not to be possible, I would like to target this for early in 18.04 LTS cycle.

CVE References

Rik Mills (rikmills)
summary: - Update to evi2 version 0.26
+ Update to eviv2 version 0.26
summary: - Update to eviv2 version 0.26
+ Update to exiv2 version 0.26
tags: added: upgrade-software-version
Jeremy Bícha (jbicha)
Changed in exiv2 (Ubuntu):
importance: Undecided → Wishlist
status: New → Triaged
Revision history for this message
Simon Quigley (tsimonq2) wrote : Re: Update to exiv2 version 0.26

Bump, was anything done with this?

Revision history for this message
Rik Mills (rikmills) wrote :

Seems not

Revision history for this message
Jeremy Bícha (jbicha) wrote :

At this point, this would require a Feature Freeze Exception to be considered for Ubuntu 18.04 LTS.

https://wiki.ubuntu.com/FreezeExceptionProcess

You would need to be sure that you would be able to complete the transition:
https://people.canonical.com/~ubuntu-archive/transitions/html/exiv2.html

Also, why don't you ask the Debian maintainer why this was uploaded to experimental but not unstable yet?

no longer affects: exiv2 (Ubuntu Bionic)
Revision history for this message
Ari (ari-reads) wrote :

Exiv2 0.25 as used by ubuntu 18.04 and the upcoming 18.10 is really obsolete and this brings all kinds of annoying problems with darktable - inability to recognize lenses and so on.

Even the current package in 18.10 is obsolete.

Revision history for this message
Sebastien Bacher (seb128) wrote :

The update is still in Debian/experimental and require a transition
https://release.debian.org/transitions/html/auto-exiv2.html
Unsure if it's worth trying to do in Ubuntu before Debian though

tags: added: version-blocked
Revision history for this message
Jeremy Bícha (jbicha) wrote :
Revision history for this message
Jeremy Bícha (jbicha) wrote :

Several of those issues are fixed at https://github.com/Exiv2/exiv2 but it's going to be a bit of work to handle all of that in Debian or Ubuntu.

Revision history for this message
Ari (ari-reads) wrote :

Thanks Jeremy. It's a bit challenging for anyone doing photography work with recent hardware. Key apps like darktable and digicam rely on this library and ubuntu/debian are way behind. Last year's fedora had 0.26.

Flatpaks could help, I tried darktable's and it includes an updated exiv2, but it has a huge drawback, OpenCL doesnt work with flatpaks (or snaps) yet, so its useless in my case (my photography workstation is built specifically for photo editing with opencl)

I guess there is no choice but to try and build exiv2 manually and hope the system doesnt break :)

Changed in exiv2 (Debian):
status: Unknown → Fix Released
tags: removed: version-blocked
summary: - Update to exiv2 version 0.26
+ Update to exiv2 version 0.27
tags: added: version-blocked-ff
tags: removed: version-blocked-ff
Revision history for this message
Rik Mills (rikmills) wrote :

Is this going to be actioned for 20.04?

Revision history for this message
Ari (ari-reads) wrote :

it doesn't look like it's going to be actioned at all,

focal (graphics): EXIF/IPTC/XMP metadata manipulation tool [universe]
0.25-4ubuntu3: amd64 arm64 armhf ppc64el s390x

which is awful, unfortunately. It's been 3 years now without an update. Not only for the security implications and all the known vulnerabilities but also for the problems this brings to other photography software that depends on exiv2, e.g. lensfun and all the apps that use lensfun, like darktable

Revision history for this message
Rik Mills (rikmills) wrote :

exiv2 (0.27.2-7) just landed in debian unstable

Rik Mills (rikmills)
Changed in exiv2 (Ubuntu Focal):
status: Triaged → Fix Committed
Revision history for this message
Rico Tzschichholz (ricotz) wrote :

Note that 0.27.2-8ubutnu1 dropped the previously applied patch for CVE-2019-17402 which is still required!

Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

reuploaded thanks Rico!

Revision history for this message
Gianfranco Costamagna (costamagnagianfranco) wrote :

I got tricked because the very same patch was applied on the function 10 lines above...

Revision history for this message
Martin Wimpress  (flexiondotorg) wrote :
Changed in exiv2 (Ubuntu Focal):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.