PT-2017-3960 · Exempi+5 · Exempi+5
Hubert Figuière
·
Publicado
2017-08-14
·
Atualizado
2019-10-03
·
CVE-2017-18238
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Exempi versions prior to 2.4.4
Description
The issue is related to the
TradQT Manager::ParseCachedBoxes function, which allows remote attackers to cause a denial of service, potentially through an infinite loop or use-after-free error, via crafted XMP data in a .qt file.Recommendations
For Exempi versions prior to 2.4.4, update to version 2.4.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
TradQT Manager::ParseCachedBoxes function until a patch is available. Avoid using crafted XMP data in .qt files to minimize the risk of exploitation.Exploit
Correção
DoS
Infinite Loop
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Exempi
Red Hat
Suse
Ubuntu