exempi: denial of service via opening of crafted webp file
Published Aug 22, 2023
6.5
MEDIUMCVSS 3.1
EPSS 1.00%
Description
Buffer Overflow vulnerability in WEBP_Support.cpp in exempi 2.5.0 and earlier allows remote attackers to cause a denial of service via opening of crafted webp file.
Affected products
No data.
- ≤ 2.5.0
No data.
Red Hat Enterprise Linux 8
exempi-0:2.4.5-4.el8
Fixed · RHSA-2024:3066
Red Hat Enterprise Linux 6
exempi
Out of support scope
Red Hat Enterprise Linux 7
exempi
Out of support scope
Red Hat Enterprise Linux 9
exempi
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | exempi-0:2.4.5-4.el8 | Fixed | RHSA-2024:3066 |
| Red Hat Enterprise Linux 6 | exempi | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | exempi | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | exempi | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2020-18652 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2235673 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-10576 Advisory
- https://gitlab.freedesktop.org/libopenraw/exempi/commit/acee2894ceb91616543927c2a6e45050c60f98f7 Patch
- https://gitlab.freedesktop.org/libopenraw/exempi/issues/12 ExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00032.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2020-18652
- https://www.cve.org/CVERecord?id=CVE-2020-18652
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-18652 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2235673 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-10576 | Advisory | |
| https://gitlab.freedesktop.org/libopenraw/exempi/commit/acee2894ceb91616543927c2a6e45050c60f98f7 | Patch | |
| https://gitlab.freedesktop.org/libopenraw/exempi/issues/12 | ExploitIssue TrackingThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/09/msg00032.html | mailing-list | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-18652 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-18652 |
Change history (0)
No recorded changes yet.