Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10 Buster: DLA-3585-1 Moderate: Exempi Buffer Overflow Advisory

debian lts
Calendar Grey September 25, 2023
Dist Debian Esm H88
Upgrade the Exempi package on your Debian LTS installation to enhance security as per DLA-3585-1. This update addresses vulnerabilities threatening system integrity
Multiple vulneratibilities were found in exempi, an implementation of XMP (Extensible Metadata Platform)

Summary

CVE-2020-18651

A Buffer Overflow vulnerability was found
in function ID3_Support::ID3v2Frame::getFrameValue
allows remote attackers to cause a denial of service.

CVE-2020-18652

A Buffer Overflow vulnerability was found in
WEBP_Support.cpp allows remote attackers to cause a
denial of service.

CVE-2021-36045

An out-of-bounds read vulnerability was found
that could lead to disclosure of arbitrary memory.

CVE-2021-36046

A memory corruption vulnerability was found,
potentially resulting in arbitrary code execution
in the context of the current use

CVE-2021-36047

An Improper Input Validation vulnerability was found,
potentially resulting in arbitrary
code execution in the context of the current use.

CVE-2021-36048

An Improper Input Validation was found,
potentially resulting in arbitrary
code execution in the context of the current user.

CVE-2021-36050

A buffer overflow vulnerability was found,

Read the Full Advisory


Package: exempi
Version: 2.5.0-2+deb10u1
CVE ID: CVE-2020-18651 CVE-2020-18652 CVE-2021-36045 CVE-2021-36046

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here