Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-7728

Опубликовано: 22 фев. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/interfaces/MD5.cpp.

An out-of-bounds read vulnerability has been discovered in Exempi in the way it handles Extensible Metadata Platform (XMP) data in TIFF images. An attacker could cause a denial of service by convincing a user to open a crafted TIFF image file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6exempiNot affected
Red Hat Enterprise Linux 7exempiNot affected
Red Hat Enterprise Linux 8exempiNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1555155exempi: Heap-based buffer overflow in third-party/zuid/interfaces/MD5.cpp:MD5Update() allows for denial of service via crafted TIFF image

EPSS

Процентиль: 65%
0.005
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/interfaces/MD5.cpp.

CVSS3: 5.5
nvd
почти 8 лет назад

An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/interfaces/MD5.cpp.

CVSS3: 5.5
debian
почти 8 лет назад

An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileH ...

CVSS3: 5.5
github
больше 3 лет назад

An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/interfaces/MD5.cpp.

suse-cvrf
почти 8 лет назад

Security update for exempi

EPSS

Процентиль: 65%
0.005
Низкий

3.3 Low

CVSS3

Уязвимость CVE-2018-7728