USN-7266-1: digiKam vulnerabilities

Post Reply
Shane1145
Posts: 1689
Joined: Wed Sep 25, 2024 2:31 pm

USN-7266-1: digiKam vulnerabilities

Post by Shane1145 »

Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in digiKam, did not correctly parse certain files. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2017-0691)

It was discovered that Platinum Upnp SDK, vendored in digiKam, was vulnerable to a path traversal attack. An attacker could possibly use this
issue to leak sensitive information. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-19858).

https://ubuntu.com/security/notices/USN-7266-1
Post Reply