First published: Wed Sep 29 2021(Updated: )
XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe XMP Toolkit Software Development Kit | <=2021.07 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40716 has a high severity due to the potential for sensitive memory disclosure.
To fix CVE-2021-40716, update to the latest version of the Adobe XMP Toolkit SDK beyond version 2021.07.
CVE-2021-40716 affects users of Adobe XMP Toolkit SDK versions 2021.07 and earlier, as well as Debian Linux 10.0.
CVE-2021-40716 is classified as an out-of-bounds read vulnerability.
An attacker can exploit CVE-2021-40716 to disclose sensitive memory and potentially bypass mitigations like ASLR.