cbcvebase.
CVE-2021-42528
published 2022-05-02

CVE-2021-42528: XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected

8 ranges
VendorProductVersion rangeFixed in
adobexmp_toolkitunspecified – 2021.07
adobexmp_toolkit_software_development_kit<= 2021.07
debiandebian_linux
debianexempi< exempi 2.6.0-1 (bookworm)exempi 2.6.0-1 (bookworm)
exempi_projectexempi>= 0 < 2.5.2-1+deb11u12.5.2-1+deb11u1
exempi_projectexempi>= 0 < 2.6.0-12.6.0-1
exempi_projectexempi>= 0 < 2.6.0-12.6.0-1
exempi_projectexempi>= 0 < 2.6.0-12.6.0-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM