CVE-2018-7729: Medium severity Exempi Project Exempi vulnerability
An issue was discovered in Exempi through 2.4.4. There is a stack-based buffer over-read in the PostScriptMetaHandler::ParsePSFile() function in XMPFiles/source/FileHandlers/PostScriptHandler.cpp.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/exempito a version that resolves this vulnerability.Fixed in 2.5.2-1Fixed in 2.5.2-1+deb11u1Fixed in 2.6.3-1Fixed in 2.6.6-2 - Upgrade
Upgrade
Exempito a version that resolves this vulnerability.Fixed in 2.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7729?
CVE-2018-7729 is rated as a moderate severity vulnerability due to its potential for causing stack-based buffer over-read.
How do I fix CVE-2018-7729?
To fix CVE-2018-7729, you should upgrade to Exempi versions 2.5.2-1, 2.6.3-1, or 2.6.5-1 or newer.
Which software is affected by CVE-2018-7729?
CVE-2018-7729 affects Exempi versions up to 2.4.4 and certain versions of Ubuntu Linux, including 14.04, 16.04, and 17.10.
Where can I find more information about CVE-2018-7729?
Additional information regarding CVE-2018-7729 can be found in security advisories and software repositories.
Is CVE-2018-7729 exploitable remotely?
CVE-2018-7729 is not considered remotely exploitable as it requires local access to trigger the buffer over-read.