ALT-PU-2019-1112-1
Closed vulnerabilities
Published: 2018-06-22
BDU:2020-04528
Уязвимость функции WEBP::GetLE32 утилиты «exempi», позволяющая нарушителю вызвать отказ в обслуживании
Severity: HIGH (7.5)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity: HIGH (7.1)
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C
References:
Published: 2018-06-22
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-12648
The WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Support.hpp in Exempi 2.4.5 has a NULL pointer dereference.
Severity: MEDIUM (4.3)
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
Severity: HIGH (7.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00070.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00075.html
- https://bugs.freedesktop.org/show_bug.cgi?id=106981
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00070.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00075.html
- https://bugs.freedesktop.org/show_bug.cgi?id=106981