![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.891310 |
Category: | Debian Local Security Checks |
Title: | Debian: Security Advisory (DLA-1310-1) |
Summary: | The remote host is missing an update for the Debian 'exempi' package(s) announced via the DLA-1310-1 advisory. |
Description: | Summary: The remote host is missing an update for the Debian 'exempi' package(s) announced via the DLA-1310-1 advisory. Vulnerability Insight: Various issues were discovered in exempi, a library to parse XMP metadata that may cause a denial-of-service or may have other unspecified impact via crafted files. CVE-2017-18233 An Integer overflow in the Chunk class in RIFF.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in an .avi file. CVE-2017-18234 An issue was discovered that allows remote attackers to cause a denial of service (invalid memcpy with resultant use-after-free) or possibly have unspecified other impact via a .pdf file containing JPEG data. CVE-2017-18236 The ASF_Support::ReadHeaderObject function in ASF_Support.cpp allows remote attackers to cause a denial of service (infinite loop) via a crafted .asf file. CVE-2017-18238 The TradQT_Manager::ParseCachedBoxes function in QuickTime_Support.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .qt file. CVE-2018-7728 TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in MD5.cpp. CVE-2018-7730 A certain case of a 0xffffffff length is mishandled in PSIR_FileWriter.cpp, leading to a heap-based buffer over-read in the PSD_MetaHandler::CacheFileData() function. For Debian 7 Wheezy, these problems have been fixed in version 2.2.0-1+deb7u1. We recommend that you upgrade your exempi packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: [link moved to references] Affected Software/OS: 'exempi' package(s) on Debian 7. Solution: Please install the updated package(s). CVSS Score: 6.8 CVSS Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2017-18233 https://lists.debian.org/debian-lts-announce/2018/03/msg00013.html RedHat Security Advisories: RHSA-2019:2048 https://access.redhat.com/errata/RHSA-2019:2048 https://usn.ubuntu.com/3668-1/ Common Vulnerability Exposure (CVE) ID: CVE-2017-18234 Common Vulnerability Exposure (CVE) ID: CVE-2017-18236 Common Vulnerability Exposure (CVE) ID: CVE-2017-18238 Common Vulnerability Exposure (CVE) ID: CVE-2018-7728 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BCFXKOOATZ2B5G3G7EBXZWVZHEABN4ZV/ https://bugs.freedesktop.org/show_bug.cgi?id=105205 https://cgit.freedesktop.org/exempi/commit/?id=e163667a06a9b656a047b0ec660b871f29a83c9f Common Vulnerability Exposure (CVE) ID: CVE-2018-7730 https://bugs.freedesktop.org/show_bug.cgi?id=105204 https://cgit.freedesktop.org/exempi/commit/?id=6cbd34025e5fd3ba47b29b602096e456507ce83b |
Copyright | Copyright (C) 2018 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |