PT-2017-3957 · Adobe+5 · Exempi+5
Hubert Figuière
·
Publicado
2017-08-14
·
Atualizado
2019-10-03
·
CVE-2017-18233
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Exempi versions prior to 2.4.4
Description
The issue is caused by an integer overflow in the Chunk class. This allows remote attackers to cause a denial of service, specifically an infinite loop, via crafted XMP data in a .avi file.
Recommendations
For versions prior to 2.4.4, update to version 2.4.4 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted XMP data in .avi files to minimize the risk of exploitation.
Exploit
Correção
DoS
Infinite Loop
Use After Free
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Exempi
Red Hat
Suse
Ubuntu