MGASA-2022-0420

Source
https://advisories.mageia.org/MGASA-2022-0420.html
Import Source
https://advisories.mageia.org/MGASA-2022-0420.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0420
Upstream
  • CVE-2022-3756
Published
2022-11-13T02:25:20Z
Modified
2026-04-16T04:41:34.203085934Z
Summary
Updated exiv2 packages fix security vulnerability
Details

Affected is the function QuickTimeVideo::userDataDecoder of the file quicktimevideo.cpp of the component QuickTime Video Handler. The manipulation leads to integer overflow. It is possible to launch the attack remotely. (CVE-2022-3756)

References
Credits

Affected packages

Mageia:8 / exiv2

Package

Name
exiv2
Purl
pkg:rpm/mageia/exiv2?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.27.3-1.5.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2022-0420.json"