Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18235

Опубликовано: 25 июл. 2017
Источник: redhat
CVSS3: 3.3

Описание

An issue was discovered in Exempi before 2.4.3. The VPXChunk class in XMPFiles/source/FormatSupport/WEBP_Support.cpp does not ensure nonzero widths and heights, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted .webp file.

Отчет

This issue did not affect the versions of Exempi as shipped with Red Hat Enterprise Linux 6 and 7 as they did not include support for Web/P images.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6exempiNot affected
Red Hat Enterprise Linux 7exempiNot affected
Red Hat Enterprise Linux 8exempiNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1559595exempi: assertion failure in VPXChunk class in XMPFiles/source/FormatSupport/WEBP_Support.cpp

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

An issue was discovered in Exempi before 2.4.3. The VPXChunk class in XMPFiles/source/FormatSupport/WEBP_Support.cpp does not ensure nonzero widths and heights, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted .webp file.

CVSS3: 5.5
nvd
почти 8 лет назад

An issue was discovered in Exempi before 2.4.3. The VPXChunk class in XMPFiles/source/FormatSupport/WEBP_Support.cpp does not ensure nonzero widths and heights, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted .webp file.

CVSS3: 5.5
debian
почти 8 лет назад

An issue was discovered in Exempi before 2.4.3. The VPXChunk class in ...

CVSS3: 5.5
github
больше 3 лет назад

An issue was discovered in Exempi before 2.4.3. The VPXChunk class in XMPFiles/source/FormatSupport/WEBP_Support.cpp does not ensure nonzero widths and heights, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted .webp file.

3.3 Low

CVSS3