CVE-2017-18234: Use After Free
An issue was discovered in Exempi before 2.4.3. It allows remote attackers to cause a denial of service (invalid memcpy with resultant use-after-free) or possibly have unspecified other impact via a .pdf file containing JPEG data, related to XMPFiles/source/FormatSupport/ReconcileTIFF.cpp, XMPFiles/source/FormatSupport/TIFFMemoryReader.cpp, and XMPFiles/source/FormatSupport/TIFFSupport.hpp.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/exempito a version that resolves this vulnerability.Fixed in 2.4.3 - Upgrade
Upgrade
debian/exempito a version that resolves this vulnerability.Fixed in 2.5.2-1Fixed in 2.5.2-1+deb11u1Fixed in 2.6.3-1Fixed in 2.6.6-2 - Upgrade
Upgrade
exempito a version that resolves this vulnerability.Fixed in 2.4.3
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18234?
CVE-2017-18234 has a medium severity rating due to its potential impact on system stability and security.
How do I fix CVE-2017-18234?
To fix CVE-2017-18234, update Exempi to version 2.4.3 or later for Red Hat, or to 2.5.2-1, 2.6.3-1, or 2.6.5-1 for Debian.
What types of attacks can occur due to CVE-2017-18234?
CVE-2017-18234 can allow remote attackers to cause a denial of service, specifically through an invalid memcpy leading to a use-after-free condition.
Which versions of Exempi are affected by CVE-2017-18234?
CVE-2017-18234 affects Exempi versions prior to 2.4.3.
Is there a workaround for CVE-2017-18234?
There is no specific workaround for CVE-2017-18234; the recommended action is to apply the appropriate software updates.