Infinite loop in Exempi - CVE-2017-18238
Published: April 10, 2018
Vulnerability identifier: #VU11629
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-18238
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.
The weakness exists in the TradQT_Manager::ParseCachedBoxesfunction defined in the source code file XMPFiles/source/FormatSupport/QuickTime_Support.cpp due to infinite loop when handling Extensible Metadata Platform (XMP) data in .qt files. A remote attacker can trick the victim into accessing a specially crafted .qtfile, trigger memory corruption and cause the service to crash.
The weakness exists in the TradQT_Manager::ParseCachedBoxesfunction defined in the source code file XMPFiles/source/FormatSupport/QuickTime_Support.cpp due to infinite loop when handling Extensible Metadata Platform (XMP) data in .qt files. A remote attacker can trick the victim into accessing a specially crafted .qtfile, trigger memory corruption and cause the service to crash.
Affected software
Exempi
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Opensuse
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Opensuse
How to mitigate CVE-2017-18238
Update to version 2.4.4.