Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18233

Опубликовано: 11 авг. 2017
Источник: redhat
CVSS3: 3.3

Описание

An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .avi file.

Отчет

This issue did not affect the versions of exempi as shipped with Red Hat Enterprise Linux 6 as they did not include the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6exempiNot affected
Red Hat Enterprise Linux 8exempiNot affected
Red Hat Enterprise Linux 7exempiFixedRHSA-2019:204806.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190->CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1559575exempi: Infinite Loop in Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .avi file.

CVSS3: 5.5
nvd
почти 8 лет назад

An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .avi file.

CVSS3: 5.5
debian
почти 8 лет назад

An issue was discovered in Exempi before 2.4.4. Integer overflow in th ...

CVSS3: 5.5
github
больше 3 лет назад

An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .avi file.

CVSS3: 5.5
fstec
больше 8 лет назад

Уязвимость утилиты «exempi», вызванная целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании

3.3 Low

CVSS3