Use-after-free error in Exempi - CVE-2017-18234

 

Use-after-free error in Exempi - CVE-2017-18234

Published: April 11, 2018 / Updated: April 17, 2018


Vulnerability identifier: #VU11756
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-18234
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists due to improper processing of a file that contains JPEG data related to the XMPFiles/source/FormatSupport/ReconcileTIFF.cpp, XMPFiles/source/FormatSupport/TIFF_MemoryReader.cpp and XMPFiles/source/FormatSupport/TIFF_Support.hpp source code files. A remote attacker can trick the victim into accessing a file that contains customized JPEG data that submits malicious input, trigger use after free and cause the service to crash.


Affected software

Exempi
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Fedora
exempi

How to mitigate CVE-2017-18234

Update to version 2.4.3.

exempi - update to 2.4.5-1.fc27

External References

Related Security Bulletins