NULL pointer dereference in Exempi - CVE-2018-12648
Published: June 28, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dreference error in the WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Support.hpp file. A remote attacker can use a specially crafted file to perform a denial of service (DoS) attack.
Affected software
exempi (Alpine package)
exempi (Ubuntu package)
libexempi3 (Ubuntu package)
exempi
libexempi8 (Ubuntu package)
Opensuse
Ubuntu
Fedora
How to mitigate CVE-2018-12648
exempi (Alpine package) - update to 2.5.1-r0
exempi (Ubuntu package) - addressed in versions 2.4.5-2ubuntu0.1, 2.5.1-1ubuntu0.1, 2.5.2-1ubuntu0.21.10.1, 2.5.2-1ubuntu0.22.04.1
libexempi3 (Ubuntu package) - update to 2.4.5-2ubuntu0.1
exempi - addressed in versions 2.4.5-4.fc28, 2.4.5-4.fc29
libexempi8 (Ubuntu package) - addressed in versions 2.5.1-1ubuntu0.1, 2.5.2-1ubuntu0.21.10.1, 2.5.2-1ubuntu0.22.04.1