USN-3852-1: Exiv2 vulnerabilities
It was discovered that Exiv2 incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. CVE-2017-9239 only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-11591, CVE-2017-11683, CVE-2017-14859, CVE-2017-14862, CVE-2017-14864, CVE-2017-17669, CVE-2017-9239, CVE-2018-16336, CVE-2018-1758)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-3852-1?
USN-3852-1 is classified as a vulnerability that could lead to denial of service.
How do I fix USN-3852-1?
To mitigate USN-3852-1, update the Exiv2 and libexiv2-14 packages to the latest versions provided by Ubuntu.
Which versions of Ubuntu are affected by USN-3852-1?
USN-3852-1 affects Ubuntu 14.04 LTS, 16.04 LTS, and 18.04 LTS.
What components are impacted by USN-3852-1?
USN-3852-1 primarily affects the Exiv2 package and its associated libraries.
Is there a workaround for USN-3852-1 until a fix is applied?
The recommended action is to update to the patched versions, as there are no temporary workarounds for this denial of service vulnerability.