An issue was discovered in Exempi through 2.4.4. A certain case of a 0xffffffff length is mishandled in XMPFiles/source/FormatSupport/PSIR_FileWriter.cpp, leading to a heap-based buffer over-read in the PSD_MetaHandler::CacheFileData() function.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade exempi-debuginfoUpgrade exempiUpgrade exempi-devel | Apr 27, 2020 | Mar 6, 2018 |
| Centos_linux | — | Upgrade exempi-develUpgrade exempiUpgrade exempi-debuginfo | Aug 28, 2019 | Mar 6, 2018 |
| Debian | — | Upgrade exempi | Feb 25, 2019 | Mar 6, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade exempi | Dec 4, 2019 | Mar 6, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade exempi | Dec 18, 2019 | Mar 6, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade exempi | Dec 11, 2019 | Mar 6, 2018 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Mar 6, 2018 |
| Oracle_linux | — | Upgrade exempi-develUpgrade exempi | Jul 21, 2020 | Feb 22, 2018 |
| Redhat_linux | — | Upgrade exempi-develNo solution existsUpgrade exempi-debuginfoUpgrade exempi | Aug 7, 2019 | Mar 6, 2018 |
| Suse | — | Upgrade libexempi-develUpgrade libexempi3 | Mar 20, 2018 | Mar 6, 2018 |
| Ubuntu | — | Upgrade libexempi3Upgrade exempi | Jun 12, 2018 | Mar 6, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub