CVE-2016-6328 log

Source
Severity Medium
Remote No
Type Information disclosure
Description
A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metadata, even other applications' private data).
Group Package Affected Fixed Severity Status Ticket
AVG-1166 libexif 0.6.21-1 0.6.22-1 High Fixed
References
https://github.com/libexif/libexif/commit/41bd04234b104312f54d25822f68738ba8d7133d
https://github.com/libexif/libexif/commit/435e21f05001fb03f9f186fa7cbc69454afd00d1
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-6328