Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 29: FEDORA-2018-d8824aeec5 Moderate Exempi Denial Of Service

fedora
Calendar Grey October 7, 2018
Dist Fedora Esm H88
A security patch for Exempi in Fedora 29 addresses a NULL pointer dereference vulnerability that could result in a denial of service incident. Discover further details.
Fix for **CVE-2018-12648**.

Summary

Exempi provides a library for easy parsing of XMP metadata. It is a port of

Adobe XMP SDK to work on UNIX and to be build with GNU automake.

It includes XMPCore and XMPFiles.

Fix for **CVE-2018-12648**.

[ 1 ] Bug #1594643 - CVE-2018-12648 exempi: NULL pointer dereference in WEBP_Support.hpp:WEBP::GetLE32() allows for denial of service [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1594643

su -c 'dnf upgrade --advisory FEDORA-2018-d8824aeec5' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 29
Version: 2.4.5
Release: 4.fc29
Summary: Library for easy parsing of XMP metadata

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here