First published: Thu Jan 10 2019(Updated: )
It was discovered that Exiv2 incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. CVE-2017-9239 only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-11591, CVE-2017-11683, CVE-2017-14859, CVE-2017-14862, CVE-2017-14864, CVE-2017-17669, CVE-2017-9239, CVE-2018-16336, CVE-2018-1758)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/exiv2 | <0.25-4ubuntu0.1 | 0.25-4ubuntu0.1 |
Ubuntu OpenSSH Client | =18.10 | |
All of | ||
ubuntu/libexiv2-14 | <0.25-4ubuntu0.1 | 0.25-4ubuntu0.1 |
Ubuntu OpenSSH Client | =18.10 | |
All of | ||
ubuntu/exiv2 | <0.25-3.1ubuntu0.18.04.2 | 0.25-3.1ubuntu0.18.04.2 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/libexiv2-14 | <0.25-3.1ubuntu0.18.04.2 | 0.25-3.1ubuntu0.18.04.2 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/exiv2 | <0.25-2.1ubuntu16.04.3 | 0.25-2.1ubuntu16.04.3 |
Ubuntu OpenSSH Client | =16.04 | |
All of | ||
ubuntu/libexiv2-14 | <0.25-2.1ubuntu16.04.3 | 0.25-2.1ubuntu16.04.3 |
Ubuntu OpenSSH Client | =16.04 | |
All of | ||
ubuntu/exiv2 | <0.23-1ubuntu2.2 | 0.23-1ubuntu2.2 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/libexiv2-12 | <0.23-1ubuntu2.2 | 0.23-1ubuntu2.2 |
Ubuntu OpenSSH Client | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
USN-3852-1 is classified as a vulnerability that could lead to denial of service.
To mitigate USN-3852-1, update the Exiv2 and libexiv2-14 packages to the latest versions provided by Ubuntu.
USN-3852-1 affects Ubuntu 14.04 LTS, 16.04 LTS, and 18.04 LTS.
USN-3852-1 primarily affects the Exiv2 package and its associated libraries.
The recommended action is to update to the patched versions, as there are no temporary workarounds for this denial of service vulnerability.