CVE-2018-7728: Medium severity Exempi Project Exempi vulnerability
An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFFHandler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/interfaces/MD5.cpp.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/exempito a version that resolves this vulnerability.Fixed in 2.5.2-1Fixed in 2.5.2-1+deb11u1Fixed in 2.6.3-1Fixed in 2.6.6-2 - Upgrade
Upgrade
Exempito a version that resolves this vulnerability.Fixed in 2.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7728?
CVE-2018-7728 has a medium severity rating due to the potential for heap-based buffer over-read vulnerabilities.
How do I fix CVE-2018-7728?
To fix CVE-2018-7728, upgrade Exempi to versions 2.5.2-1, 2.6.3-1, or 2.6.5-1 or later.
Which versions of Exempi are affected by CVE-2018-7728?
Exempi versions up to and including 2.4.4 are affected by CVE-2018-7728.
Is CVE-2018-7728 specific to certain operating systems?
Yes, CVE-2018-7728 affects specific distributions like Debian and Ubuntu.
What component of Exempi is vulnerable in CVE-2018-7728?
The vulnerability in CVE-2018-7728 is in the TIFF_Handler.cpp, particularly how it handles zero-length cases.