PT-2017-3960 · Exempi+5 · Exempi+5
Hubert Figuière
·
Published
2017-08-14
·
Updated
2019-10-03
·
CVE-2017-18238
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Exempi versions prior to 2.4.4
Description
The issue is related to the
TradQT Manager::ParseCachedBoxes function, which allows remote attackers to cause a denial of service, potentially through an infinite loop or use-after-free error, via crafted XMP data in a .qt file.Recommendations
For Exempi versions prior to 2.4.4, update to version 2.4.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
TradQT Manager::ParseCachedBoxes function until a patch is available. Avoid using crafted XMP data in .qt files to minimize the risk of exploitation.Exploit
Fix
DoS
Infinite Loop
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Exempi
Red Hat
Suse
Ubuntu