First published: Wed Oct 13 2021(Updated: )
XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memory locations and causing a local denial of service in the context of the current user. User interaction is required to exploit this vulnerability in that the victim will need to open a specially crafted MXF file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe XMP Toolkit | <=2020.1 | |
Debian | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40732 is classified as a high severity vulnerability due to its potential to cause a local denial of service and data leakage.
To resolve CVE-2021-40732, upgrade to the latest version of the Adobe XMP Toolkit that addresses this vulnerability.
CVE-2021-40732 affects Adobe XMP Toolkit version 2020.1 and earlier, as well as Debian Linux version 10.0.
CVE-2021-40732 is a null pointer dereference vulnerability that requires user interaction to be exploited.
Exploitation of CVE-2021-40732 can lead to local denial of service and data leakage from certain memory locations.