CVE-2017-18237: Null Pointer Dereference
Published Mar 15, 2018
·Updated
An issue was discovered in Exempi before 2.4.3. The PostScriptSupport::ConvertToDate function in XMPFiles/source/FormatSupport/PostScriptSupport.cpp allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via a crafted .ps file.
Affected Software
1 affected component
Exempi Project Exempi<2.4.3
Remediation
Event History
Mar 15, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18237?
CVE-2017-18237 has a severity level that can lead to denial of service due to an invalid pointer dereference.
2
How do I fix CVE-2017-18237?
To fix CVE-2017-18237, upgrade Exempi to version 2.4.3 or later.
3
What type of vulnerability is CVE-2017-18237?
CVE-2017-18237 is a denial of service vulnerability that affects the PostScript_Support function in Exempi.
4
What causes the denial of service in CVE-2017-18237?
The denial of service in CVE-2017-18237 is caused by processing a crafted .ps file that leads to an application crash.
5
In which software versions is CVE-2017-18237 found?
CVE-2017-18237 is found in Exempi versions prior to 2.4.3.