CVE-2017-18235Improper Input Validation in Project Exempi

Severity
5.5MEDIUMNVD
EPSS
0.4%
top 38.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 15
Latest updateMay 14

Description

An issue was discovered in Exempi before 2.4.3. The VPXChunk class in XMPFiles/source/FormatSupport/WEBP_Support.cpp does not ensure nonzero widths and heights, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted .webp file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Debianexempi_project/exempi< 2.4.3-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4p29-x5hq-25mf: An issue was discovered in Exempi before 22022-05-14
OSV
CVE-2017-18235: An issue was discovered in Exempi before 22018-03-15
CVEList
CVE-2017-18235: An issue was discovered in Exempi before 22018-03-15

📋Vendor Advisories

2
Red Hat
exempi: assertion failure in VPXChunk class in XMPFiles/source/FormatSupport/WEBP_Support.cpp2017-07-25
Debian
CVE-2017-18235: exempi - An issue was discovered in Exempi before 2.4.3. The VPXChunk class in XMPFiles/s...2017

💬Community

2
Bugzilla
CVE-2017-18233 CVE-2017-18234 CVE-2017-18235 CVE-2017-18236 CVE-2017-18237 exempi: various flaws [fedora-all]2018-03-22
Bugzilla
CVE-2017-18235 exempi: assertion failure in VPXChunk class in XMPFiles/source/FormatSupport/WEBP_Support.cpp2018-03-22
CVE-2017-18235 — Improper Input Validation | cvebase