PT-2018-3554 · Adobe+4 · Exempi+4

Xiao

·

Publicado

2018-06-22

·

Atualizado

2024-06-15

·

CVE-2018-12648

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Exempi version 2.4.5
Description: The issue is related to a NULL pointer dereference error in the WEBP::GetLE32 function, located in XMPFiles/source/FormatSupport/WEBP Support.hpp. This could allow a remote attacker to cause a denial of service.
Recommendations: For Exempi version 2.4.5, consider disabling the WEBP::GetLE32 function as a temporary workaround until a patch is available. Restrict access to the WEBP Support.hpp module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1112
AZL-44871
BDU:2020-04528
CVE-2018-12648
MGASA-2018-0416
OPENSUSE-SU-2019:1649-1
OPENSUSE-SU-2019:1657-1
OPENSUSE-SU-2019_1649-1
OPENSUSE-SU-2019_1657-1
OPENSUSE-SU-2024:10745-1
SUSE-SU-2019:1603-1
SUSE-SU-2019_1603-1
USN-5483-1

Produtos afetados

Alt Linux
Exempi
Linuxmint
Suse
Ubuntu