Infinite loop in Exempi - CVE-2017-18236

 

Infinite loop in Exempi - CVE-2017-18236

Published: April 18, 2018


Vulnerability identifier: #VU11880
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-18236
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists in the ASF_Support::ReadHeaderObject function in the source code file XMPFiles/source/FormatSupport/ASF_Support.cpp due to infinite loop when handling .asf files. A remote attacker can trick the victim into accessing a specially crafted .asf file and cause the service to crash.

Affected software

Exempi
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Fedora
Opensuse
exempi

How to mitigate CVE-2017-18236

Update to version 2.4.4.

exempi - update to 2.4.5-1.fc27

External References

Related Security Bulletins