Comment 50 for bug 1941752

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package exiv2 - 0.27.3-3ubuntu4.1

---------------
exiv2 (0.27.3-3ubuntu4.1) impish-security; urgency=medium

  * SECURITY REGRESSION: out of range access that may cause a crash
    - debian/patches/CVE-2021-37620-4.patch: fix out of range access that may
      cause a crash (LP: #1941752)
    - debian/patches/CVE-2021-37620-5.patch: backport to C++98 (a str.pop_back
      that was added in C++11)
    - Thanks Simon Schmeißer

 -- Leonidas Da Silva Barbosa <email address hidden> Mon, 10 Jan 2022 10:28:12 -0300