CVE-2017-18235: Input Validation
Published Mar 15, 2018
·Updated
An issue was discovered in Exempi before 2.4.3. The VPXChunk class in XMPFiles/source/FormatSupport/WEBPSupport.cpp does not ensure nonzero widths and heights, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted .webp file.
Affected Software
1 affected component
Exempi Project Exempi<2.4.3
Remediation
Event History
Mar 15, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18235?
CVE-2017-18235 is classified as a denial of service vulnerability due to assertion failure leading to application exit.
2
How do I fix CVE-2017-18235?
To fix CVE-2017-18235, upgrade Exempi to version 2.4.3 or later.
3
What software is affected by CVE-2017-18235?
CVE-2017-18235 affects Exempi versions earlier than 2.4.3.
4
Can CVE-2017-18235 be exploited remotely?
Yes, CVE-2017-18235 can be exploited remotely through crafted .webp files.
5
What is the impact of CVE-2017-18235 on applications?
The impact of CVE-2017-18235 is that affected applications may crash due to an assertion failure.