First published: Thu Mar 15 2018(Updated: )
An issue was discovered in Exempi before 2.4.4. An integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .avi file. Reference: <a href="https://bugs.freedesktop.org/show_bug.cgi?id=102151">https://bugs.freedesktop.org/show_bug.cgi?id=102151</a> Patch: <a href="https://cgit.freedesktop.org/exempi/commit/?id=65a8492832b7335ffabd01f5f64d89dec757c260">https://cgit.freedesktop.org/exempi/commit/?id=65a8492832b7335ffabd01f5f64d89dec757c260</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exempi Project Exempi | <2.4.4 | |
Debian Debian Linux | =7.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
redhat/exempi | <2.4.4 | 2.4.4 |
debian/exempi | 2.5.2-1 2.6.3-1 2.6.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.