First published: Wed Sep 01 2021(Updated: )
XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe XMP Toolkit Software Development Kit | <=2020.1 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36053 is classified as a medium severity vulnerability.
To fix CVE-2021-36053, update the affected Adobe XMP Toolkit SDK to version 2020.2 or later.
CVE-2021-36053 affects Adobe XMP Toolkit SDK versions up to and including 2020.1 and Debian Linux 10.0.
Exploitation of CVE-2021-36053 requires user interaction.
CVE-2021-36053 is an out-of-bounds read vulnerability that can lead to memory disclosure.