First published: Wed Sep 01 2021(Updated: )
XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe XMP Toolkit | <=2020.1 | |
Debian | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36045 is rated as a medium severity vulnerability due to its potential to allow arbitrary memory disclosure.
To fix CVE-2021-36045, upgrade to a post-2020.1 version of the Adobe XMP Toolkit SDK or apply relevant patches provided by your Linux distribution.
The potential impacts of CVE-2021-36045 include the ability for attackers to disclose sensitive information from memory.
Yes, exploitation of CVE-2021-36045 requires user interaction.
CVE-2021-36045 affects Adobe XMP Toolkit SDK versions 2020.1 and earlier.