QID 671126

Date Published: 2021-11-29

QID 671126: EulerOS Security Update for exempi (EulerOS-SA-2019-2524)

Exempi provides a library for easy parsing of xmp metadata.
It is a port of adobe xmp sdk to work on unix and to be build with gnu automake.
It includes xmpcore and xmpfiles.
Security fix(es): an issue was discovered in exempi through 2.4.4.
A certain case of a 0xffffffff length is mishandled in xmpfiles/source/formatsupport/psir_filewriter.cpp, leading to a heap-based buffer over-read in the psd_metahandler::cachefiledata() function.(cve-2018-7730)

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

An arbitrary attacker may exploit this vulnerability to compromise the system.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    The Vendor has released a security update to fix the vulnerability. For more information please visit EulerOS-SA-2019-2524 for updates and patch information

    CVEs related to QID 671126

    Software Advisories
    Advisory ID Software Component Link
    EulerOS-SA-2019-2524 EulerOS V2.0SP5 URL Logo developer.huaweicloud.com/ict/en/site-euleros/euleros/security-advisories/EulerOS-SA-2019-2524