CVE-2017-18233: Integer Overflow
An issue was discovered in Exempi before 2.4.4. An integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .avi file.
Reference: https://bugs.freedesktop.org/showbug.cgi?id=102151
Patch: https://cgit.freedesktop.org/exempi/commit/?id=65a8492832b7335ffabd01f5f64d89dec757c260
Other sources
An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .avi file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/exempito a version that resolves this vulnerability.Fixed in 2.4.4 - Upgrade
Upgrade
debian/exempito a version that resolves this vulnerability.Fixed in 2.5.2-1Fixed in 2.5.2-1+deb11u1Fixed in 2.6.3-1Fixed in 2.6.6-2 - Upgrade
Upgrade
Exempito a version that resolves this vulnerability.Fixed in 2.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18233?
CVE-2017-18233 has a medium severity rating, primarily due to its potential to cause a denial of service.
How do I fix CVE-2017-18233?
To remediate CVE-2017-18233, upgrade Exempi to version 2.4.4 or later.
What are the affected software versions for CVE-2017-18233?
CVE-2017-18233 affects Exempi versions prior to 2.4.4 on various platforms.
What kind of attack does CVE-2017-18233 facilitate?
CVE-2017-18233 allows attackers to exploit an integer overflow to create an infinite loop leading to a denial of service.
What systems are at risk from CVE-2017-18233?
Systems running Exempi versions before 2.4.4, including specific Debian and Ubuntu OS versions, are at risk from CVE-2017-18233.