CVE-2018-7731: Null Pointer Dereference
An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FormatSupport/WEBPSupport.cpp does not check whether a bitstream has a NULL value, leading to a NULL pointer dereference in the WEBP::VP8XChunk class.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/exempito a version that resolves this vulnerability.Fixed in 2.5.2-1Fixed in 2.5.2-1+deb11u1Fixed in 2.6.3-1Fixed in 2.6.6-2 - Upgrade
Upgrade
exempito a version that resolves this vulnerability.Fixed in 2.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7731?
CVE-2018-7731 has been classified as a medium severity vulnerability due to the potential for NULL pointer dereference.
How do I fix CVE-2018-7731?
To fix CVE-2018-7731, upgrade to Exempi version 2.5.2-1 or later.
Which versions of Exempi are affected by CVE-2018-7731?
Exempi versions up to and including 2.4.4 are affected by CVE-2018-7731.
What impact does CVE-2018-7731 have on systems?
CVE-2018-7731 can lead to application crashes or unexpected behavior due to a NULL pointer dereference.
Is CVE-2018-7731 present in major Linux distributions?
Yes, CVE-2018-7731 affects Exempi installations in various Linux distributions including Ubuntu.